Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2025-45753
A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP…
Vtiger Crm
Mitigation only
MEDIUM 6.1
CVE-2025-45755
A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An at…
Vtiger Crm
Mitigation only
MEDIUM 6.1
CVE-2025-1618
A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/…
Vtiger Crm
7.0+
MEDIUM 6.1
CVE-2024-54687
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
Vtiger Crm
after 6.1
MEDIUM 5.4
CVE-2024-48119
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
Vtiger Crm
No fix yet
CRITICAL 9.6
CVE-2024-44777
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary…
Vtiger Crm
No fix yet
CRITICAL 9.6
CVE-2024-44778
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitr…
Vtiger Crm
No fix yet
CRITICAL 9.6
CVE-2024-44779
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbi…
Vtiger Crm
No fix yet
MEDIUM 6.1
CVE-2024-44776
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
Vtiger Crm
No fix yet
HIGH 8.3
CVE-2024-42995
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module …
Vtiger Crm
after 8.1.0
HIGH 7.2
CVE-2024-42994
VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" oper…
Vtiger Crm
after 8.1.0
HIGH 8.1
CVE-2023-46304
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint …
Vtiger Crm
Patch available
HIGH 8.8
CVE-2023-38891
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function …
Vtiger Crm
Mitigation only
MEDIUM 5.4
CVE-2022-38335
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
Vtiger Crm
after 7.4.0
CRITICAL 9.8
CVE-2020-22807
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
Vtiger Crm
No fix yet
MEDIUM 6.5
CVE-2020-19363
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
Vtiger Crm
No fix yet
MEDIUM 6.1
CVE-2020-19362
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users…
Vtiger Crm
No fix yet
HIGH 8.8
CVE-2013-3591EPSS 43%
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Vtiger Crm
No fix yet
HIGH 8.8
CVE-2015-6000EPSS 40%
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p…
Vtiger Crm
after 6.3.0
CRITICAL 9.8
CVE-2013-3215EPSS 69%
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Vtiger Crm
after 5.4.0
CRITICAL 9.8
CVE-2013-3214EPSS 85%
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
Vtiger Crm
after 5.4.0
HIGH 8.1
CVE-2013-3212EPSS 8%
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execu…
Vtiger Crm
after 5.4.0
HIGH 8.8
CVE-2019-19202
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding …
Vtiger Crm
7.2.0+
MEDIUM 6.1
CVE-2018-8047
vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vuln…
Vtiger Crm
after 7.0.1
HIGH 8.8
CVE-2016-10754
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
Vtiger Crm
No fix yet
HIGH 8.8
CVE-2019-11057
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
Vtiger Crm
after 7.0.1
HIGH 7.2
CVE-2019-5009EPSS 10%
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and …
Vtiger Crm
after 7.1.0
HIGH 7.3
CVE-2016-1713EPSS 17%
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p…
Vtiger Crm
No fix yet
HIGH 8.1
CVE-2016-4834
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users …
Vtiger Crm
after 6.4.0
MEDIUM 5.0
CVE-2014-2268EPSS 31%
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in…
Vtiger Crm
No fix yet