VYPR
Vendor

Vtiger

Products
4
CVEs
76
Across products
148
Status
Private

Products

4

Recent CVEs

76
View all 76 CVEs →
  • CVE-2013-3214CriJan 28, 2020
    risk 0.73cvss 9.8epss 0.85

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

  • CVE-2013-3215CriJan 29, 2020
    risk 0.72cvss 9.8epss 0.69

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

  • CVE-2020-22807CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

  • CVE-2013-3591HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.43

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

  • CVE-2015-6000HigFeb 6, 2020
    risk 0.63cvss 8.8epss 0.40

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an…

  • CVE-2024-44779CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2024-44778CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2024-44777CriAug 29, 2024
    risk 0.62cvss 9.6epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • CVE-2023-38891HigSep 14, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

  • CVE-2019-19202HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.01

    In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

  • CVE-2016-10754HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

  • CVE-2019-11057HigMay 17, 2019
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

  • CVE-2013-3212HigJan 28, 2020
    risk 0.56cvss 8.1epss 0.08

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

  • CVE-2024-42995HigAug 16, 2024
    risk 0.54cvss 8.3epss 0.00

    VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

  • CVE-2023-46304HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.02

    modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

  • CVE-2016-4834HigAug 1, 2016
    risk 0.53cvss 8.1epss 0.02

    modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.

  • CVE-2016-1713HigApr 14, 2017
    risk 0.52cvss 7.3epss 0.17

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an…

  • CVE-2019-5009HigJan 4, 2019
    risk 0.51cvss 7.2epss 0.10

    Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a…

  • CVE-2025-45753HigMay 21, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

  • CVE-2024-42994HigAug 16, 2024
    risk 0.47cvss 7.2epss 0.00

    VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.