CVE-2020-28961: Perfexcrm Perfex CRM
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.
Affected products
- Perfexcrm Perfex CRM: version 2.4.4 only
Published 2021-10-22. Last modified 2026-06-17.