Looking for the vulnerability index of Invicti's legacy products?
EspoCRM Relative Path Traversal Vulnerability - CVE-2026-33733 - Vulnerability Database

EspoCRM Relative Path Traversal Vulnerability - CVE-2026-33733

High
Reference: CVE-2026-33733
Title: EspoCRM Relative Path Traversal Vulnerability
Overview:

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4 the admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. As a result an authenticated admin can use ../ sequences to escape the intended template directory and read create overwrite or delete arbitrary files that resolve to body.tpl or subject.tpl under the web application user39s filesystem permissions. Version 9.3.4 fixes the issue.