<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://docs.lime-crm.com/lib/exe/css.php?s=feed" type="text/css"?>
<rss version="2.0">
    <channel xmlns:g="http://base.google.com/ns/1.0">
        <title>Lime CRM Wiki security</title>
        <description></description>
        <link>https://docs.lime-crm.com/</link>
        <lastBuildDate>Tue, 28 Apr 2026 13:44:23 +0000</lastBuildDate>
        <generator>FeedCreator 1.8</generator>
        <image>
            <url>https://docs.lime-crm.com/ttps://docs.lime-crm.com/lib/tpl/bootstrap3/images/favicon.ico</url>
            <title>Lime CRM Wiki</title>
            <link>https://docs.lime-crm.com/</link>
        </image>
        <item>
            <title>Security update for Lime CRM Server</title>
            <link>https://docs.lime-crm.com/security/lcsec18-01?rev=1543788558&amp;do=diff</link>
            <description>Security update for Lime CRM Server

 Bulletin ID

LCSEC18-01

 Date published

2018-07-05

 Priority

2

 Severity

Critical

Priority and severity ratings are determined as described here.

Summary

This security update resolves a vulnerability in Lime CRM Server. The vulnerability could allow remote code execution in Lime CRM Server if an attacker alters the system configuration in a malicious way. However, an attacker would need access to a user account with  administrator privileges in orde…</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Sun, 02 Dec 2018 22:09:18 +0000</pubDate>
        </item>
        <item>
            <title>Security update for Lime CRM Desktop Client</title>
            <link>https://docs.lime-crm.com/security/lcsec20-01?rev=1608561535&amp;do=diff</link>
            <description>Security update for Lime CRM Desktop Client

 Bulletin ID

LCSEC20-01

 Date published

2020-12-21

 Priority

2

 Severity

Critical

Priority and severity ratings are determined as described here.

Summary

This security update resolved a vulnerability in Lime CRM Desktop Client. The vulnerability enables local Windows users to execute programs with elevated privileges.</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Mon, 21 Dec 2020 14:38:55 +0000</pubDate>
        </item>
        <item>
            <title>Security implications of Apache Log4j vulnerabilities</title>
            <link>https://docs.lime-crm.com/security/lcsec21-01?rev=1677489988&amp;do=diff</link>
            <description>Security implications of Apache Log4j vulnerabilities

 Bulletin ID

LCSEC21-01

 Date published

2021-12-12

 Priority

1

 Severity

Important

Priority and severity ratings are determined as described here.

Activity log
 Date   Update   2021-12-21 10.39</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Mon, 27 Feb 2023 09:26:28 +0000</pubDate>
        </item>
        <item>
            <title>Security Patch for Lime BI - Information Disclosure Vulnerability</title>
            <link>https://docs.lime-crm.com/security/lcsec26-01?rev=1771593151&amp;do=diff</link>
            <description>Security Patch for Lime BI - Information Disclosure Vulnerability

Overview

A security vulnerability has been identified in Metabase (the underlying platform for Lime BI) that could potentially allow authenticated users to extract sensitive information, including database credentials, under certain circumstances.</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Fri, 20 Feb 2026 13:12:31 +0000</pubDate>
        </item>
        <item>
            <title>Security Patch for Lime BI - Remote Code Execution Vulnerability</title>
            <link>https://docs.lime-crm.com/security/lcsec26-02?rev=1774955043&amp;do=diff</link>
            <description>Security Patch for Lime BI - Remote Code Execution Vulnerability

Overview

A security vulnerability has been identified in Metabase (the underlying platform for Lime BI) that could potentially allow authenticated administrators to achieve Remote Code Execution (RCE) and Arbitrary File Read under certain circumstances.</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Tue, 31 Mar 2026 11:04:03 +0000</pubDate>
        </item>
        <item>
            <title>Priority and severity ratings</title>
            <link>https://docs.lime-crm.com/security/ratings?rev=1543788558&amp;do=diff</link>
            <description>Priority and severity ratings

This is a guideline to help our customers prioritize updates and to assess the security impact of known software vulnerabilities.

Priority ratings

The definitions of the priority ratings are:
 Priority   Definition    1</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Sun, 02 Dec 2018 22:09:18 +0000</pubDate>
        </item>
        <item>
            <title>Security Bulletins and Advisories</title>
            <link>https://docs.lime-crm.com/security/start?rev=1774969637&amp;do=diff</link>
            <description>Security Bulletins and Advisories

This page contains important information regarding security vulnerabilities that could affect specific versions of Lime CRM. Use this information to take the corrective actions prescribed. In our effort to serve you better, you can also</description>
            <author>anonymous@undisclosed.example.com (Anonymous)</author>
        <category>security</category>
            <pubDate>Tue, 31 Mar 2026 15:07:17 +0000</pubDate>
        </item>
    </channel>
</rss>
