Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vtiger Crm MEDIUM 6.4
CVE-2014-2269EPSS 16%

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a reques…

Patch available
Fix from $1,600 2014-04-22
Vtiger Crm HIGH 7.5
CVE-2013-3213

Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklis…

No fix yet
Fix from $1,950 2014-04-02
Vtiger Crm MEDIUM 6.5
CVE-2013-5091

SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL…

Fix: after 5.4.0
Fix from $1,600 2013-10-04
Vtiger Crm MEDIUM 5.0
CVE-2012-4867

Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote attackers to read arbitrary fil…

No fix yet
Fix from $1,600 2012-09-06
Vtiger Crm HIGH 7.5
CVE-2011-4559

SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the …

Fix: after 5.2.1
Fix from $1,950 2011-11-28
Vtiger Crm MEDIUM 6.8
CVE-2010-3910EPSS 7%

Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow …

Fix: after 5.2.0
Fix from $1,600 2010-11-26
Vtiger Crm MEDIUM 6.0
CVE-2010-3909

Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by u…

Fix: after 5.2.0
Fix from $1,600 2010-11-26
Vtiger Crm HIGH 9.0
CVE-2009-3258

vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie…

Mitigation only
Fix from $1,950 2009-09-18
Vtiger Crm HIGH 9.0
CVE-2009-3250EPSS 11%

The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary cod…

No fix yet
Fix from $1,950 2009-09-18
Vtiger Crm HIGH 7.5
CVE-2009-3249EPSS 10%

Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot do…

No fix yet
Fix from $1,950 2009-09-18
Vtiger Crm MEDIUM 6.8
CVE-2009-3248

Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u…

No fix yet
Fix from $1,600 2009-09-18
Vtiger Crm MEDIUM 5.0
CVE-2008-3458

Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail …

Fix: after 5.0.3
Fix from $1,600 2008-08-04
Vtiger Crm HIGH 8.5
CVE-2007-3599

vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permis…

Fix: after 5.0.2
Fix from $1,950 2007-07-06
Vtiger Crm MEDIUM 6.5
CVE-2007-3603

SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute …

Fix: after 5.0.2
Fix from $1,600 2007-07-06
Vtiger Crm MEDIUM 6.5
CVE-2007-3616

index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain …

Fix: after 5.0.2
Fix from $1,600 2007-07-06
Vtiger Crm MEDIUM 5.5
CVE-2007-3598

index.php in vtiger CRM before 5.0.3 allows remote authenticated users to obtain all users' names and e-mail addresses, and possibly change user sett…

Fix: after 5.0.2
Fix from $1,600 2007-07-06
Vtiger Crm MEDIUM 5.5
CVE-2007-3602

The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with i…

Fix: after 5.0.2
Fix from $1,600 2007-07-06
Vtiger Crm HIGH 7.5
CVE-2006-5289EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2006-10-13
Vtiger Crm HIGH 7.5
CVE-2006-4617

Unrestricted file upload vulnerability in fileupload.html in vtiger CRM 4.2.4, and possibly earlier versions, allows remote attackers to upload and e…

Fix: after 4.2.4
Fix from $1,950 2006-09-07
Vtiger Crm HIGH 7.5
CVE-2006-4588

vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to in…

No fix yet
Fix from $1,950 2006-09-06
Vtiger Crm MEDIUM 6.8
CVE-2006-4587

Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script …

Mitigation only
Fix from $1,600 2006-09-06
Vtiger Crm HIGH 7.5
CVE-2005-3819

Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authenticatio…

Fix: after 4.2
Fix from $1,950 2005-11-26
Vtiger Crm HIGH 7.5
CVE-2005-3822

Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username in…

Fix: after 4.2
Fix from $1,950 2005-11-26
Vtiger Crm HIGH 7.5
CVE-2005-3823

The Users module in vTiger CRM 4.2 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary file in the templatename parame…

Fix: after 4.2
Fix from $1,950 2005-11-26
Vtiger Crm MEDIUM 6.4
CVE-2005-3820

Multiple directory traversal vulnerabilities in index.php in vTiger CRM 4.2 and earlier allow remote attackers to read or include arbitrary files, an…

Fix: after 4.2
Fix from $1,600 2005-11-26
Vtiger Crm MEDIUM 5.0
CVE-2005-3824

The uploads module in vTiger CRM 4.2 and earlier allows remote attackers to upload arbitrary files, such as PHP files, via the add2db action.

Fix: after 4.2
Fix from $1,600 2005-11-26