Files
espocrm/.github/SECURITY.md
2026-04-17 15:23:27 +03:00

705 B

Security Policy

Reporting a vulnerability

If you believe you have discovered a vulnerability in EspoCRM, please contact us via this or this forms. Or create a private vulnerability report on GitHub.

What reports we do not accept:

  • Executing PHP code by an extension or during the installation or upgrade process.
  • Exposing contacts though a target list, campaign or mass email, considering the user has access to them.
  • SSRF in IMAP/SMTP with TOCTOU.

Supported versions

For severe vulnerabilities we provide fixes for 2 minor versions (the second number in the version string) back from the current stable version.