CVE-2020-28961: Perfexcrm Perfex CRM

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.

Affected products

Published 2021-10-22. Last modified 2026-06-17.