Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yetiforce Customer Relationship Management MEDIUM 6.5
CVE-2023-49508

Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensiti…

Fix: 6.5.0+
Fix from $1,600 2024-02-16
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-3002

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-10-06
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-3005

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-09-20
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-3004

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-09-20
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-3000

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-09-20
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-2924

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

Fix: 6.3.0+
Fix from $1,600 2022-09-20
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-2829

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-08-23
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-2890

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-08-22
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2022-1340

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Fix: 6.4.0+
Fix from $1,600 2022-08-22
Yetiforce Customer Relationship Management MEDIUM 6.1
CVE-2022-1411

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able …

Fix: 6.4.0+
Fix from $1,600 2022-05-05
Yetiforce Customer Relationship Management HIGH 8.0
CVE-2022-0269

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

Fix: 6.3.0+
Fix from $1,950 2022-01-24
Yetiforce Customer Relationship Management MEDIUM 6.1
CVE-2021-4121

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: after 6.3.0
Fix from $1,600 2021-12-16
Yetiforce Customer Relationship Management MEDIUM 5.4
CVE-2021-4116

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: after 6.3.0
Fix from $1,600 2021-12-15
Yetiforce Customer Relationship Management MEDIUM 6.1
CVE-2021-4107

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: after 6.3.0
Fix from $1,600 2021-12-14