Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-45753 A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP… Vtiger Crm Mitigation only Fix from $1,9502025-05-21 MEDIUM 6.1 CVE-2025-45755 A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An at… Vtiger Crm Mitigation only Fix from $1,6002025-05-21 MEDIUM 6.1 CVE-2025-1618 A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/… Vtiger Crm 7.0+ Fix from $1,6002025-02-24 MEDIUM 6.1 CVE-2024-54687 Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. Vtiger Crm after 6.1 Fix from $1,6002025-01-10 MEDIUM 5.4 CVE-2024-48119 Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. Vtiger Crm No fix yet Fix from $1,6002024-10-14 CRITICAL 9.6 CVE-2024-44777 A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary… Vtiger Crm No fix yet Fix from $2,3002024-08-29 CRITICAL 9.6 CVE-2024-44778 A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitr… Vtiger Crm No fix yet Fix from $2,3002024-08-29 CRITICAL 9.6 CVE-2024-44779 A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbi… Vtiger Crm No fix yet Fix from $2,3002024-08-29 MEDIUM 6.1 CVE-2024-44776 An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. Vtiger Crm No fix yet Fix from $1,6002024-08-29 HIGH 8.3 CVE-2024-42995 VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module … Vtiger Crm after 8.1.0 Fix from $1,9502024-08-16 HIGH 7.2 CVE-2024-42994 VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" oper… Vtiger Crm after 8.1.0 Fix from $1,9502024-08-16 HIGH 8.1 CVE-2023-46304 modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint … Vtiger Crm Patch available Fix from $1,9502024-04-30 HIGH 8.8 CVE-2023-38891 SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function … Vtiger Crm Mitigation only Fix from $1,9502023-09-14 MEDIUM 5.4 CVE-2022-38335 Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules. Vtiger Crm after 7.4.0 Fix from $1,6002022-09-27 CRITICAL 9.8 CVE-2020-22807 An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. Vtiger Crm No fix yet Fix from $2,3002021-04-29 MEDIUM 6.5 CVE-2020-19363 Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. Vtiger Crm No fix yet Fix from $1,6002021-01-20 MEDIUM 6.1 CVE-2020-19362 Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users… Vtiger Crm No fix yet Fix from $1,6002021-01-20 HIGH 8.8 CVE-2013-3591EPSS 43% vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability Vtiger Crm No fix yet Fix from $1,9502020-02-07 HIGH 8.8 CVE-2015-6000EPSS 40% Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p… Vtiger Crm after 6.3.0 Fix from $1,9502020-02-06 CRITICAL 9.8 CVE-2013-3215EPSS 69% vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. Vtiger Crm after 5.4.0 Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-3214EPSS 85% vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. Vtiger Crm after 5.4.0 Fix from $2,3002020-01-28 HIGH 8.1 CVE-2013-3212EPSS 8% vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execu… Vtiger Crm after 5.4.0 Fix from $1,9502020-01-28 HIGH 8.8 CVE-2019-19202 In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding … Vtiger Crm 7.2.0+ Fix from $1,9502019-11-21 MEDIUM 6.1 CVE-2018-8047 vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vuln… Vtiger Crm after 7.0.1 Fix from $1,6002019-06-06 HIGH 8.8 CVE-2016-10754 modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter. Vtiger Crm No fix yet Fix from $1,9502019-05-24 HIGH 8.8 CVE-2019-11057 SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands. Vtiger Crm after 7.0.1 Fix from $1,9502019-05-17 HIGH 7.2 CVE-2019-5009EPSS 10% Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and … Vtiger Crm after 7.1.0 Fix from $1,9502019-01-04 HIGH 7.3 CVE-2016-1713EPSS 17% Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p… Vtiger Crm No fix yet Fix from $1,9502017-04-14 HIGH 8.1 CVE-2016-4834 modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users … Vtiger Crm after 6.4.0 Fix from $1,9502016-08-01 MEDIUM 5.0 CVE-2014-2268EPSS 31% views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in… Vtiger Crm No fix yet Fix from $1,6002014-11-16