VYPR

CRM

by Vtiger

CVEs (35)

  • CVE-2013-3215CriJan 29, 2020
    risk 0.72cvss 9.8epss 0.69

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

  • CVE-2020-22807CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

  • CVE-2024-44779CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2024-44778CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2024-44777CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2023-38891HigSep 14, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

  • CVE-2024-42995HigAug 16, 2024
    risk 0.54cvss 8.3epss 0.00

    VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

  • CVE-2023-46304HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.02

    modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

  • CVE-2019-5009HigJan 4, 2019
    risk 0.51cvss 7.2epss 0.10

    Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a…

  • CVE-2024-42994HigAug 16, 2024
    risk 0.47cvss 7.2epss 0.00

    VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.

  • CVE-2020-19363MedJan 20, 2021
    risk 0.43cvss 6.5epss 0.04

    Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.

  • CVE-2026-26460MedApr 13, 2026
    risk 0.40cvss 6.1epss 0.00

    A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into…

  • CVE-2024-54687MedJan 10, 2025
    risk 0.40cvss 6.1epss 0.00

    Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

  • CVE-2024-44776MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

  • CVE-2020-19362MedJan 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

  • CVE-2025-70936MedApr 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an…

  • CVE-2024-48119MedOct 14, 2024
    risk 0.35cvss 5.4epss 0.00

    Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

  • CVE-2025-1618MedFeb 24, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely.…

  • CVE-2009-3249Sep 18, 2009
    risk 0.04cvss epss 0.10

    Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter to graph.php; or the (2) module or (3) file parameter to include/Ajax/CommonAjax.php, reachable…

  • CVE-2006-5289Oct 13, 2006
    risk 0.04cvss epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or (3)…

Page 1 of 2