CVE-2025-55903
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.
Published 2025-10-10. Last modified 2026-06-17.