CVE-2026-33741
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline documents through both the attachment and image entry points, resulting in stored cross-user XSS reachable through a normal attachment workflow. Although inline SVG script is blocked by the response CSP, the same CSP still allows same-origin external script. As a result, an attacker can upload a malicious SVG together with a second attacker-controlled JavaScript attachment, then trick another user into opening the SVG to execute JavaScript in the victim's EspoCRM origin. This issue has been fixed in version 9.3.4.
- Affected products
- Espocrm
- Fix
- Available
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 0.2% (11th percentile)
- Weakness
- CWE-79
- NVD status
- Deferred
- Published
- 2026-05-19
No indexed exploits for CVE-2026-33741 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-33741 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.