Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/feelec-yishu/feelcrm-os

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

CVE-2026-105290 is a server-side request forgery (SSRF) vulnerability in feelcrm-os version 1.0.0. The flaw exists in the getCurlData endpoint within the GoogleController.class.php file. An attacker can remotely manipulate the 'url' argument to cause the server to make unauthorized requests. The vulnerability has a medium severity with a CVSS score of 6.9. The issue was reported to the project but no response or patch has been provided yet. Public exploit details are available, though no active exploitation in the wild is confirmed.

Join the discussion

CVE-2026-105289 is a cross-site scripting (XSS) vulnerability in feelcrm-os version 1.0.0. The issue exists in the htmlspecialchars_decode function within the Create Customer Endpoint, specifically in the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php. An attacker can remotely manipulate the customer_form[remark] argument to execute XSS attacks. The vulnerability has a medium severity score of 5.1 and an exploit has been publicly disclosed. The vendor has been informed but has not yet responded or issued a patch.

Join the discussion

CVE-2026-105288 is a cross-site scripting (XSS) vulnerability in feelcrm-os version 1.0.0. The flaw exists in the IndexController::index function within the App/ThinkPHP/Common/functions.php file, specifically in the handling of the redirect_url argument. This vulnerability allows remote attackers to inject malicious scripts. The issue has been publicly disclosed, but the vendor has not yet responded or provided a fix.

Join the discussion
0

CVE-2026-105287 is a medium severity SQL injection vulnerability in feelcrm-os version 1.0.0. The flaw exists in the getMemberByGroups endpoint within the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php. It allows remote attackers to manipulate the groups[] argument to perform SQL injection. An exploit has been published, but no vendor response or patch is currently available.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/feelec-yishu/feelcrm-os
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses