5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
CVE-2026-33657 - EspoCRM 9.3.3 Stored HTML Injection in Email Notifications Authenticated proof-of-concept for stored HTML injection in EspoCRM 9.3.3 email notifications. Summary EspoCRM 9.3.3 renders stream-note notification emails by transforming the...
Basic Information
ID
9CC09B00-098C-5B90-82A6-E55F0B6AEA64
Published
May 11, 2026 at 20:39
Modified
May 11, 2026 at 20:44