fat_free_crm
An open source, Ruby on Rails customer relationship management platform
Activity
- Latest release
- 4mo ago
- Total releases
- 51
- Cadence
- ~9 days
- Last 12 months
- 3
Details
- License
- MIT
- First release
- Mar 10, 2012
| Version | Released | |
|---|---|---|
0.28.0
minor
|
0.28.0
minor
Dependencies (37)
+ 29 more |
|
0.27.0
minor
|
0.27.0
minor
Dependencies (36)
+ 28 more |
|
0.26.0
minor
|
0.26.0
minor
Dependencies (36)
+ 28 more |
|
0.25.0
minor
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.25.0
minor
Dependencies (35)
+ 27 more |
|
0.24.3
patch
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.24.3
patch
Dependencies (35)
+ 27 more |
|
0.24.2
patch
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.24.2
patch
Dependencies (35)
+ 27 more |
|
0.24.1
patch
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.24.1
patch
Dependencies (35)
+ 27 more |
|
0.24.0
minor
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.24.0
minor
Dependencies (35)
+ 27 more |
|
0.23.0
minor
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.23.0
minor
Dependencies (35)
+ 27 more |
|
0.22.1
patch
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.22.1
patch
Dependencies (35)
+ 27 more |
|
0.22.0
minor
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.22.0
minor
Dependencies (35)
+ 27 more |
|
0.21.0
minor
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.21.0
minor
Dependencies (34)
+ 26 more |
|
0.20.1
patch
1 CVE
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev |
0.20.1
patch
Dependencies (35)
+ 27 more |
|
0.20.0
minor
2 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.20.0
minor
Dependencies (35)
+ 27 more |
|
0.19.2
patch
2 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.19.2
patch
Dependencies (35)
+ 27 more |
|
0.19.0
minor
2 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.19.0
minor
Dependencies (35)
+ 27 more |
|
0.18.2
patch
2 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.18.2
patch
Dependencies (36)
+ 28 more |
|
0.14.2
patch
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.14.2
patch
Dependencies (34)
+ 26 more |
|
0.15.2
patch
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.15.2
patch
Dependencies (34)
+ 26 more |
|
0.18.1
patch
2 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.18.1
patch
Dependencies (36)
+ 28 more |
|
0.16.4
patch
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.16.4
patch
Dependencies (36)
+ 28 more |
|
0.17.3
patch
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.17.3
patch
Dependencies (36)
+ 28 more |
|
0.18.0
minor
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.18.0
minor
Dependencies (36)
+ 28 more |
|
0.17.2
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.17.2
patch
Dependencies (36)
+ 28 more |
|
0.15.1
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.15.1
patch
Dependencies (34)
+ 26 more |
|
0.16.3
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.16.3
patch
Dependencies (36)
+ 28 more |
|
0.14.1
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.14.1
patch
Dependencies (34)
+ 26 more |
|
0.16.2
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.16.2
patch
Dependencies (36)
+ 28 more |
|
0.17.1
minor
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.17.1
minor
Dependencies (36)
+ 28 more |
|
0.16.1
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.16.1
patch
Dependencies (36)
+ 28 more |
|
0.16.0
minor
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.16.0
minor
Dependencies (36)
+ 28 more |
|
0.15.0
minor
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.15.0
minor
Dependencies (34)
+ 26 more |
|
0.15.0.beta.2
pre
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.15.0.beta.2
pre
Dependencies (34)
+ 26 more |
|
0.14.0
minor
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.14.0
minor
Dependencies (34)
+ 26 more |
|
0.15.0.beta
pre
3 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.15.0.beta
pre
Dependencies (34)
+ 26 more |
|
0.13.6
patch
4 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.6
patch
Dependencies (28)
+ 20 more |
|
0.13.5
patch
5 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.5
patch
Dependencies (28)
+ 20 more |
|
0.13.4
patch
5 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.4
patch
Dependencies (28)
+ 20 more |
|
0.13.3
patch
5 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.3
patch
Dependencies (27)
+ 19 more |
|
0.13.2
patch
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.2
patch
Dependencies (27)
+ 19 more |
|
0.12.3
patch
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.12.3
patch
Dependencies (27)
+ 19 more |
|
0.13.1
patch
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.1
patch
Dependencies (26)
+ 18 more |
|
0.12.2
patch
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.12.2
patch
Dependencies (27)
+ 19 more |
|
0.12.1
patch
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.12.1
patch
Dependencies (27)
+ 19 more |
|
0.13.0
minor
6 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.13.0
minor
Dependencies (26)
+ 18 more |
|
0.12.0
minor
11 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-7222
GHSA-g897-cgfc-7q8v
May 17, 2022
Fat Free CRM has fixed token value
Medium
Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2013-7224
GHSA-4xq9-vw89-p5cx
May 17, 2022
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
Medium
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7223
GHSA-mcvq-7xjq-46x6
May 17, 2022
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
Medium
Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7249
GHSA-f25h-3mj6-4jpg
May 17, 2022
Fat Free CRM vulnerable to Exposure of Sensitive Information
Medium
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7225
GHSA-9ggp-5rf4-x7q9
May 17, 2022
Fat Free CRM vulnerable to SQL Injection
Medium
Multiple SQL injection vulnerabilities in Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.12.0
minor
Dependencies (27)
+ 19 more |
|
0.11.4
patch
11 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-7222
GHSA-g897-cgfc-7q8v
May 17, 2022
Fat Free CRM has fixed token value
Medium
Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2013-7224
GHSA-4xq9-vw89-p5cx
May 17, 2022
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
Medium
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7223
GHSA-mcvq-7xjq-46x6
May 17, 2022
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
Medium
Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7249
GHSA-f25h-3mj6-4jpg
May 17, 2022
Fat Free CRM vulnerable to Exposure of Sensitive Information
Medium
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7225
GHSA-9ggp-5rf4-x7q9
May 17, 2022
Fat Free CRM vulnerable to SQL Injection
Medium
Multiple SQL injection vulnerabilities in Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.11.4
patch
Dependencies (27)
+ 19 more |
|
0.11.2
patch
11 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-7222
GHSA-g897-cgfc-7q8v
May 17, 2022
Fat Free CRM has fixed token value
Medium
Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2013-7224
GHSA-4xq9-vw89-p5cx
May 17, 2022
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
Medium
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7223
GHSA-mcvq-7xjq-46x6
May 17, 2022
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
Medium
Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7249
GHSA-f25h-3mj6-4jpg
May 17, 2022
Fat Free CRM vulnerable to Exposure of Sensitive Information
Medium
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7225
GHSA-9ggp-5rf4-x7q9
May 17, 2022
Fat Free CRM vulnerable to SQL Injection
Medium
Multiple SQL injection vulnerabilities in Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.11.2
patch
Dependencies (24)
+ 16 more |
|
0.11.3
patch
11 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-7222
GHSA-g897-cgfc-7q8v
May 17, 2022
Fat Free CRM has fixed token value
Medium
Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2013-7224
GHSA-4xq9-vw89-p5cx
May 17, 2022
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
Medium
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7223
GHSA-mcvq-7xjq-46x6
May 17, 2022
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
Medium
Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7249
GHSA-f25h-3mj6-4jpg
May 17, 2022
Fat Free CRM vulnerable to Exposure of Sensitive Information
Medium
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7225
GHSA-9ggp-5rf4-x7q9
May 17, 2022
Fat Free CRM vulnerable to SQL Injection
Medium
Multiple SQL injection vulnerabilities in Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.11.3
patch
Dependencies (24)
+ 16 more |
|
0.11.1
patch
11 CVEs
GHSA-9pm8-vwc5-w2hm
Apr 14, 2026
Fat Free CRM has BOLA in DELETE /emails/:id - Any authenticated user can hit this endpoint and delete emails by ID
Low
Network
Low
Low
ImpactAuthenticated users can delete emails imported into the system assigned to another user; where the Email Dropbox is in use. PatchesFixed in v0.26.0 WorkaroundsDisable use of email dropbox. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 36 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
Fixed in
0.26.0
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2022-39281
GHSA-p75c-5x3h-cxcg
Oct 07, 2022
Fat Free CRM vulnerable to Remote Denial of Service via Tasks endpoint
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactAn authenticated user can perform a remote Denial of Service attack against Fat Free CRM. This vulnerability has been assigned the CVE identifier: CVE-2022-39281 Affected versions: All Not affected: None Fixed versions: 0.20.1 All users running an affected release should either upgrade or apply the patch immediately. ReleasesFixed versions: 0.20.1 and above PatchesIf you are unable to upgrade immediately, you should apply the following patch.
CreditsThanks to @p- for reporting this and working with us to responsibly disclose this vulnerability. Further informationIf you have any questions or comments about this advisory, please Open an issue in GitHub Issue Tracker Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 26 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
0.18.1
0.18.2
0.19.0
0.19.2
0.20.0
Fixed in
0.20.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-7222
GHSA-g897-cgfc-7q8v
May 17, 2022
Fat Free CRM has fixed token value
Medium
Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2013-7224
GHSA-4xq9-vw89-p5cx
May 17, 2022
Fat Free CRM allows remote attackers to obtain sensitive information via a direct request
Medium
Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7223
GHSA-mcvq-7xjq-46x6
May 17, 2022
Fat Free CRM contains Cross-site Request Forgery vulnerablilities
Medium
Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7249
GHSA-f25h-3mj6-4jpg
May 17, 2022
Fat Free CRM vulnerable to Exposure of Sensitive Information
Medium
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2013-7225
GHSA-9ggp-5rf4-x7q9
May 17, 2022
Fat Free CRM vulnerable to SQL Injection
Medium
Multiple SQL injection vulnerabilities in Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
Fixed in
0.12.1
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2014-5441
GHSA-wcfx-3m6v-4frg
May 17, 2022
Fat Free CRM subject to Cross-site Scripting
Medium
Multiple cross-site scripting (XSS) vulnerabilities in Affected versions
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
Fixed in
0.13.3
References
Updated Dec 03, 2024 · Source: OSV.dev
CVE-2015-1585
GHSA-wx7c-8j35-mpg8
May 14, 2022
Fat Free CRM Cross-Site Request Forgery vulnerability
Medium
Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account. Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 3 more Show less
0.13.3
0.13.4
0.13.5
Fixed in
0.13.6
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2018-20975
GHSA-4p8f-mmfj-r45g
Aug 21, 2019
Cross-site scripting in fat_free_crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Fat Free CRM before 0.18.1 has XSS in the Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 21 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0.beta
0.15.0.beta.2
0.15.1
0.15.2
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.17.1
0.17.2
0.17.3
0.18.0
Fixed in
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000842
GHSA-j5rj-g695-342r
Dec 20, 2018
Fat Free CRM vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
FatFreeCRM version Affected versions
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2
+ 15 more Show less
0.13.3
0.13.4
0.13.5
0.13.6
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.16.1
0.16.2
0.16.3
0.17.1
0.17.2
0.18.0
Fixed in
0.14.2
0.15.2
0.16.4
0.17.3
0.18.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
0.11.1
patch
Dependencies (31)
+ 23 more |