FAIL › dossier
crmeb
VENDOR· dossier confidence 20%
CRMEB is a Chinese SaaS vendor for private domain e-commerce systems with a documented history of critical remote code execution vulnerabilities. Its software has suffered multiple high-severity flaws including arbitrary file uploads and SSRF-based RCEs, indicating a pattern of insufficient security hardening in its core components.
PROFILE
Categorysoftware vendorWhat they doCRMEB is a Chinese software vendor that develops and distributes private domain membership e-commerce systems and related SaaS products.
Websitehttps://www.crmeb.com ↗
SECURITY POSTURE
The vendor has a poor security track record, with multiple critical remote code execution (RCE) vulnerabilities discovered in its core software versions between 2020 and 2023.
Notable failures
- CVE-2023-30185 arbitrary file upload RCE
- CVE-2020-25466 SSRF RCE
Patterns: repeated critical RCE vulnerabilities in core components; unpatched edge-device and interface RCEs
Reputationsevere-fallout (-0.30) · 7 trusted sources
CoverageNVD · NVD · chromereleases.googleblog.com · cooey · cvefeed.io · www.cvefind.com
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-05-08 | CVE-2023-30185 | critical | CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. |
| 2023-05-08 | CVE-2023-30185 | critical | CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. |
| 2020-10-23 | CVE-2020-25466 | critical | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. |
| 2020-10-23 | CVE-2020-25466 | critical | A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CRMEB's vulnerability was confirmed exploited and added to CISA KEV, indicating critical risk and regulatory scrutiny.
Confirmed critical SSRF flaw enabling remote code execution
"A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code."
Cataloged as a known vulnerability for tracking
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
Mirrors CISA KEV, highlighting active exploitation
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management."
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
DOSSIER SOURCES
- Salesforce - Wikipedia · en.wikipedia.org
- Company Overview, The Cheesecake Factory Incorporated · investors.thecheesecakefactory.com
- 赢万元现金!Crmeb 首届主题设计大赛,作品火热征集中 · www.crmeb.com
- Merck & Co. - Wikipedia · en.wikipedia.org
- 【有重大福利 】CRMEB Pro 私域会员电商系统 v4.2 公测版发布 · www.crmeb.com
Open questions: CRMEB's founding year and headquarters location · CRMEB's organizational size and ownership structure · CRMEB's official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:52:41.900899+00:00