Skip to content
COOEY

FAIL › dossier

crmeb

VENDOR

· dossier confidence 20%

CRMEB is a Chinese SaaS vendor for private domain e-commerce systems with a documented history of critical remote code execution vulnerabilities. Its software has suffered multiple high-severity flaws including arbitrary file uploads and SSRF-based RCEs, indicating a pattern of insufficient security hardening in its core components.

PROFILE
Categorysoftware vendorWhat they doCRMEB is a Chinese software vendor that develops and distributes private domain membership e-commerce systems and related SaaS products. Websitehttps://www.crmeb.com ↗
SECURITY POSTURE

The vendor has a poor security track record, with multiple critical remote code execution (RCE) vulnerabilities discovered in its core software versions between 2020 and 2023.

Notable failures
  • CVE-2023-30185 arbitrary file upload RCE
  • CVE-2020-25466 SSRF RCE
Patterns: repeated critical RCE vulnerabilities in core components; unpatched edge-device and interface RCEs
Reputationsevere-fallout (-0.30) · 7 trusted sources CoverageNVD · NVD · chromereleases.googleblog.com · cooey · cvefeed.io · www.cvefind.com
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2023-05-08 CVE-2023-30185 critical CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
2023-05-08 CVE-2023-30185 critical CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
2020-10-23 CVE-2020-25466 critical A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
2020-10-23 CVE-2020-25466 critical A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
CRMEB's vulnerability was confirmed exploited and added to CISA KEV, indicating critical risk and regulatory scrutiny.
cooey ↗severe-fallout-0.90
Confirmed critical SSRF flaw enabling remote code execution
"A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code."
www.cvefind.com ↗severe-fallout-0.50
Cataloged as a known vulnerability for tracking
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
cvefeed.io ↗severe-fallout-0.70
Mirrors CISA KEV, highlighting active exploitation
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management."
Irrelevant to CRMEB vulnerability
Irrelevant to CRMEB vulnerability
NVD ↗severe-fallout+0.00
Irrelevant to CRMEB vulnerability
NVD ↗severe-fallout+0.00
Irrelevant to CRMEB vulnerability
Open questions: CRMEB's founding year and headquarters location · CRMEB's organizational size and ownership structure · CRMEB's official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:52:41.900899+00:00