CVE-2014-7986: Espocrm

Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.

install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.

Affected products

  • Espocrm Espocrm: up to and including 2.5.2

Published 2014-10-31. Last modified 2026-06-17.