CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.