Skip to content
Noroxi

Vtiger records

72 published records for vendor vtiger.

All records

72 records
  • CVE-2013-3214
    64This week

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    CriticalCVSS 9.8WeaponizedEPSS 85%

    vtiger · vtiger crmJan 28, 2020

  • CVE-2013-3215
    60This week

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession

    CriticalCVSS 9.8WeaponizedEPSS 69%

    vtiger · vtiger crmJan 29, 2020

  • vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

    HighCVSS 8.8WeaponizedEPSS 43%

    vtiger · vtiger crmFeb 7, 2020

  • Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta

    HighCVSS 8.8WeaponizedEPSS 40%

    vtiger · vtiger crmFeb 6, 2020

  • CVE-2009-3250
    39Monitor

    The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbi

    CriticalCVSS 9.0Proof of conceptEPSS 11%

    vtiger · vtiger crmSep 18, 2009

  • An issue was dicovered in vtiger crm 7.2.

    CriticalCVSS 9.8No exploitEPSS 1%

    vtiger · vtiger crmApr 29, 2021

  • A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exe

    CriticalCVSS 9.6No exploitEPSS 1%

    vtiger · vtiger crmAug 29, 2024

  • A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execu

    CriticalCVSS 9.6No exploitEPSS 1%

    vtiger · vtiger crmAug 29, 2024

  • A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute

    CriticalCVSS 9.6No exploitEPSS 1%

    vtiger · vtiger crmAug 29, 2024

  • CVE-2009-3258
    37Monitor

    vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters

    CriticalCVSS 9.0No exploitEPSS 2%

    vtiger · vtiger crmSep 18, 2009

  • modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.

    HighCVSS 8.8No exploitEPSS 1%

    vtiger · vtiger crmMay 24, 2019

  • SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList

    HighCVSS 8.8Proof of conceptEPSS 1%

    vtiger · vtiger crmSep 14, 2023

  • SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

    HighCVSS 8.8No exploitEPSS 1%

    vtiger · vtiger crmMay 17, 2019

  • In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role b

    HighCVSS 8.8No exploitEPSS 1%

    vtiger · vtiger crmNov 21, 2019

  • CVE-2016-1713
    34Monitor

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta

    HighCVSS 7.3WeaponizedEPSS 17%

    vtiger · vtiger crmApr 14, 2017

  • CVE-2013-3212
    34Monitor

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files

    HighCVSS 8.1Proof of conceptEPSS 8%

    vtiger · vtiger crmJan 28, 2020

  • CVE-2007-3599
    34Monitor

    vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vi

    HighCVSS 8.5No exploitEPSS 1%

    vtiger · vtiger crmJul 6, 2007

  • CVE-2009-3249
    33Monitor

    Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .

    HighCVSS 7.5Proof of conceptEPSS 10%

    vtiger · vtiger crmSep 18, 2009

  • CVE-2016-4834
    33Monitor

    modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticat

    HighCVSS 8.1No exploitEPSS 2%

    vtiger · vtiger crmJul 31, 2016

  • VTiger CRM <= 8.1.0 does not correctly check user privileges.

    HighCVSS 8.3No exploitEPSS 0%

    vtiger · vtiger crmAug 16, 2024

  • CVE-2006-5289
    32Monitor

    Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a

    HighCVSS 7.5Proof of conceptEPSS 8%

    vtiger · vtiger crmOct 13, 2006

  • modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected

    HighCVSS 8.1Proof of conceptEPSS 2%

    vtiger · vtiger crmApr 30, 2024

  • CVE-2019-5009
    31Monitor

    Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fo

    HighCVSS 7.2Proof of conceptEPSS 10%

    vtiger · vtiger crmJan 4, 2019

  • CVE-2013-3213
    31Monitor

    Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1

    HighCVSS 7.5Proof of conceptEPSS 3%

    vtiger · vtiger crmApr 2, 2014

  • CVE-2005-3819
    31Monitor

    Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass auth

    HighCVSS 7.5Proof of conceptEPSS 3%

    vtiger · vtiger crmNov 25, 2005