Vtiger
Products
4- 72 CVEs
- 44 CVEs
- 31 CVEs
- 1 CVE
Recent CVEs
76| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-3214 | Cri | 0.73 | 9.8 | 0.85 | Jan 28, 2020 | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. | ||
| CVE-2013-3215 | Cri | 0.72 | 9.8 | 0.69 | Jan 29, 2020 | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | ||
| CVE-2020-22807 | Cri | 0.64 | 9.8 | 0.01 | Apr 29, 2021 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | ||
| CVE-2013-3591 | Hig | 0.64 | 8.8 | 0.43 | Feb 7, 2020 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | ||
| CVE-2015-6000 | Hig | 0.63 | 8.8 | 0.40 | Feb 6, 2020 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an… | ||
| CVE-2024-44779 | Cri | 0.62 | 9.6 | 0.01 | Aug 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | ||
| CVE-2024-44778 | Cri | 0.62 | 9.6 | 0.01 | Aug 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | ||
| CVE-2024-44777 | Cri | 0.62 | 9.6 | 0.01 | Aug 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | ||
| CVE-2023-38891 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2023 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php. | ||
| CVE-2019-19202 | Hig | 0.57 | 8.8 | 0.01 | Nov 21, 2019 | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. | ||
| CVE-2016-10754 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2019 | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter. | ||
| CVE-2019-11057 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2019 | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands. | ||
| CVE-2013-3212 | Hig | 0.56 | 8.1 | 0.08 | Jan 28, 2020 | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code. | ||
| CVE-2024-42995 | Hig | 0.54 | 8.3 | 0.00 | Aug 16, 2024 | VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules. | ||
| CVE-2023-46304 | Hig | 0.53 | 8.1 | 0.02 | Apr 30, 2024 | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load). | ||
| CVE-2016-4834 | Hig | 0.53 | 8.1 | 0.02 | Aug 1, 2016 | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors. | ||
| CVE-2016-1713 | Hig | 0.52 | 7.3 | 0.17 | Apr 14, 2017 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an… | ||
| CVE-2019-5009 | Hig | 0.51 | 7.2 | 0.10 | Jan 4, 2019 | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a… | ||
| CVE-2025-45753 | Hig | 0.47 | 7.2 | 0.00 | May 21, 2025 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature. | ||
| CVE-2024-42994 | Hig | 0.47 | 7.2 | 0.00 | Aug 16, 2024 | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. |
- risk 0.73cvss 9.8epss 0.85
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
- risk 0.72cvss 9.8epss 0.69
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
- risk 0.64cvss 9.8epss 0.01
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
- risk 0.64cvss 8.8epss 0.43
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
- risk 0.63cvss 8.8epss 0.40
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an…
- risk 0.62cvss 9.6epss 0.01
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
- risk 0.62cvss 9.6epss 0.01
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
- risk 0.62cvss 9.6epss 0.01
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
- risk 0.57cvss 8.8epss 0.01
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
- risk 0.57cvss 8.8epss 0.01
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
- risk 0.56cvss 8.1epss 0.08
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
- risk 0.54cvss 8.3epss 0.00
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.
- risk 0.53cvss 8.1epss 0.02
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
- risk 0.53cvss 8.1epss 0.02
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.
- risk 0.52cvss 7.3epss 0.17
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an…
- risk 0.51cvss 7.2epss 0.10
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a…
- risk 0.47cvss 7.2epss 0.00
A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.
- risk 0.47cvss 7.2epss 0.00
VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.