Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-45753 A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP… Vtiger Crm Mitigation only Fix from $1,9502025-05-21 MEDIUM 6.1 CVE-2025-45755 A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An at… Vtiger Crm Mitigation only Fix from $1,6002025-05-21 MEDIUM 5.4 CVE-2024-48119 Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. Vtiger Crm No fix yet Fix from $1,6002024-10-14 CRITICAL 9.6 CVE-2024-44777 A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary… Vtiger Crm No fix yet Fix from $2,3002024-08-29 CRITICAL 9.6 CVE-2024-44778 A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitr… Vtiger Crm No fix yet Fix from $2,3002024-08-29 CRITICAL 9.6 CVE-2024-44779 A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbi… Vtiger Crm No fix yet Fix from $2,3002024-08-29 MEDIUM 6.1 CVE-2024-44776 An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. Vtiger Crm No fix yet Fix from $1,6002024-08-29 HIGH 8.8 CVE-2023-38891 SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function … Vtiger Crm Mitigation only Fix from $1,9502023-09-14 CRITICAL 9.8 CVE-2020-22807 An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. Vtiger Crm No fix yet Fix from $2,3002021-04-29 MEDIUM 6.5 CVE-2020-19363 Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. Vtiger Crm No fix yet Fix from $1,6002021-01-20 MEDIUM 6.1 CVE-2020-19362 Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users… Vtiger Crm No fix yet Fix from $1,6002021-01-20 HIGH 8.8 CVE-2013-3591EPSS 43% vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability Vtiger Crm No fix yet Fix from $1,9502020-02-07 HIGH 8.8 CVE-2016-10754 modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter. Vtiger Crm No fix yet Fix from $1,9502019-05-24 HIGH 7.3 CVE-2016-1713EPSS 17% Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p… Vtiger Crm No fix yet Fix from $1,9502017-04-14 MEDIUM 5.0 CVE-2014-2268EPSS 31% views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in… Vtiger Crm No fix yet Fix from $1,6002014-11-16 HIGH 7.5 CVE-2013-3213 Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklis… Vtiger Crm No fix yet Fix from $1,9502014-04-02 MEDIUM 5.0 CVE-2012-4867 Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary fil… Vtiger Crm No fix yet Fix from $1,6002012-09-06 HIGH 9.0 CVE-2009-3258 vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie… Vtiger Crm Mitigation only Fix from $1,9502009-09-18 HIGH 9.0 CVE-2009-3250EPSS 11% The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary cod… Vtiger Crm No fix yet Fix from $1,9502009-09-18 HIGH 7.5 CVE-2009-3249EPSS 10% Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot do… Vtiger Crm No fix yet Fix from $1,9502009-09-18 MEDIUM 6.8 CVE-2009-3248 Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u… Vtiger Crm No fix yet Fix from $1,6002009-09-18 HIGH 7.5 CVE-2006-5289EPSS 8% Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th… Vtiger Crm No fix yet Fix from $1,9502006-10-13 HIGH 7.5 CVE-2006-4588 vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to in… Vtiger Crm No fix yet Fix from $1,9502006-09-06 MEDIUM 6.8 CVE-2006-4587 Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script … Vtiger Crm Mitigation only Fix from $1,6002006-09-06