Vtiger records
72 published records for vendor vtiger.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 6 · 8.3%
- Pre-auth RCE
- 13
- With a fix record
- 1.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
72 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2013-3214Weaponized | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Critical9.8 | — | 84.5% | Jan 28, 2020 |
60This week | CVE-2013-3215Weaponized | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSessionvtiger · vtiger crm · CWE-287 | Critical9.8 | — | 68.8% | Jan 29, 2020 |
48Plan | CVE-2013-3591Weaponized | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerabilityvtiger · vtiger crm · CWE-434 | High8.8 | — | 43.1% | Feb 7, 2020 |
47Plan | CVE-2015-6000Weaponized | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | High8.8 | — | 40.2% | Feb 6, 2020 |
39Monitor | CVE-2009-3250Proof of concept | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbivtiger · vtiger crm · CWE-20 | Critical9.0 | — | 10.9% | Sep 18, 2009 |
39Monitor | CVE-2020-22807No exploit | An issue was dicovered in vtiger crm 7.2.vtiger · vtiger crm · CWE-89 | Critical9.8 | — | 1.3% | Apr 29, 2021 |
38Monitor | CVE-2024-44779No exploit | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exevtiger · vtiger crm · CWE-79 | Critical9.6 | — | 0.8% | Aug 29, 2024 |
38Monitor | CVE-2024-44778No exploit | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuvtiger · vtiger crm · CWE-79 | Critical9.6 | — | 0.7% | Aug 29, 2024 |
38Monitor | CVE-2024-44777No exploit | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute vtiger · vtiger crm · CWE-79 | Critical9.6 | — | 0.7% | Aug 29, 2024 |
37Monitor | CVE-2009-3258No exploit | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filtersvtiger · vtiger crm · CWE-264 | Critical9.0 | — | 1.7% | Sep 18, 2009 |
35Monitor | CVE-2016-10754No exploit | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.vtiger · vtiger crm · CWE-89 | High8.8 | — | 1.4% | May 24, 2019 |
35Monitor | CVE-2023-38891Proof of concept | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList vtiger · vtiger crm · CWE-89 | High8.8 | — | 1.3% | Sep 14, 2023 |
35Monitor | CVE-2019-11057No exploit | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.vtiger · vtiger crm · CWE-89 | High8.8 | — | 1.2% | May 17, 2019 |
35Monitor | CVE-2019-19202No exploit | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role bvtiger · vtiger crm · CWE-276 | High8.8 | — | 1.0% | Nov 21, 2019 |
34Monitor | CVE-2016-1713Weaponized | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetavtiger · vtiger crm · CWE-434 | High7.3 | — | 16.6% | Apr 14, 2017 |
34Monitor | CVE-2013-3212Proof of concept | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files vtiger · vtiger crm · CWE-74 | High8.1 | — | 7.5% | Jan 28, 2020 |
34Monitor | CVE-2007-3599No exploit | vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vivtiger · vtiger crm | High8.5 | — | 1.3% | Jul 6, 2007 |
33Monitor | CVE-2009-3249Proof of concept | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .vtiger · vtiger crm · CWE-22 | High7.5 | — | 9.6% | Sep 18, 2009 |
33Monitor | CVE-2016-4834No exploit | modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticatvtiger · vtiger crm · CWE-264 | High8.1 | — | 2.2% | Jul 31, 2016 |
33Monitor | CVE-2024-42995No exploit | VTiger CRM <= 8.1.0 does not correctly check user privileges.vtiger · vtiger crm · CWE-269 | High8.3 | — | 0.4% | Aug 16, 2024 |
32Monitor | CVE-2006-5289Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a vtiger · vtiger crm | High7.5 | — | 7.9% | Oct 13, 2006 |
32Monitor | CVE-2023-46304Proof of concept | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected vtiger · vtiger crm · CWE-74 | High8.1 | — | 1.7% | Apr 30, 2024 |
31Monitor | CVE-2019-5009Proof of concept | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fovtiger · vtiger crm · CWE-434 | High7.2 | — | 9.9% | Jan 4, 2019 |
31Monitor | CVE-2013-3213Proof of concept | Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1vtiger · vtiger crm · CWE-89 | High7.5 | — | 3.1% | Apr 2, 2014 |
31Monitor | CVE-2005-3819Proof of concept | Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass authvtiger · vtiger crm | High7.5 | — | 2.8% | Nov 25, 2005 |
- CVE-2013-321464This week
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
CriticalCVSS 9.8WeaponizedEPSS 85%vtiger · vtiger crmJan 28, 2020
- CVE-2013-321560This week
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession
CriticalCVSS 9.8WeaponizedEPSS 69%vtiger · vtiger crmJan 29, 2020
- CVE-2013-359148Plan
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
HighCVSS 8.8WeaponizedEPSS 43%vtiger · vtiger crmFeb 7, 2020
- CVE-2015-600047Plan
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
HighCVSS 8.8WeaponizedEPSS 40%vtiger · vtiger crmFeb 6, 2020
- CVE-2009-325039Monitor
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbi
CriticalCVSS 9.0Proof of conceptEPSS 11%vtiger · vtiger crmSep 18, 2009
- CVE-2020-2280739Monitor
An issue was dicovered in vtiger crm 7.2.
CriticalCVSS 9.8No exploitEPSS 1%vtiger · vtiger crmApr 29, 2021
- CVE-2024-4477938Monitor
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to exe
CriticalCVSS 9.6No exploitEPSS 1%vtiger · vtiger crmAug 29, 2024
- CVE-2024-4477838Monitor
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execu
CriticalCVSS 9.6No exploitEPSS 1%vtiger · vtiger crmAug 29, 2024
- CVE-2024-4477738Monitor
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute
CriticalCVSS 9.6No exploitEPSS 1%vtiger · vtiger crmAug 29, 2024
- CVE-2009-325837Monitor
vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters
CriticalCVSS 9.0No exploitEPSS 2%vtiger · vtiger crmSep 18, 2009
- CVE-2016-1075435Monitor
modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
HighCVSS 8.8No exploitEPSS 1%vtiger · vtiger crmMay 24, 2019
- CVE-2023-3889135Monitor
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList
HighCVSS 8.8Proof of conceptEPSS 1%vtiger · vtiger crmSep 14, 2023
- CVE-2019-1105735Monitor
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
HighCVSS 8.8No exploitEPSS 1%vtiger · vtiger crmMay 17, 2019
- CVE-2019-1920235Monitor
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role b
HighCVSS 8.8No exploitEPSS 1%vtiger · vtiger crmNov 21, 2019
- CVE-2016-171334Monitor
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDeta
HighCVSS 7.3WeaponizedEPSS 17%vtiger · vtiger crmApr 14, 2017
- CVE-2013-321234Monitor
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files
HighCVSS 8.1Proof of conceptEPSS 8%vtiger · vtiger crmJan 28, 2020
- CVE-2007-359934Monitor
vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the Vi
HighCVSS 8.5No exploitEPSS 1%vtiger · vtiger crmJul 6, 2007
- CVE-2009-324933Monitor
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .
HighCVSS 7.5Proof of conceptEPSS 10%vtiger · vtiger crmSep 18, 2009
- CVE-2016-483433Monitor
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticat
HighCVSS 8.1No exploitEPSS 2%vtiger · vtiger crmJul 31, 2016
- CVE-2024-4299533Monitor
VTiger CRM <= 8.1.0 does not correctly check user privileges.
HighCVSS 8.3No exploitEPSS 0%vtiger · vtiger crmAug 16, 2024
- CVE-2006-528932Monitor
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a
HighCVSS 7.5Proof of conceptEPSS 8%vtiger · vtiger crmOct 13, 2006
- CVE-2023-4630432Monitor
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected
HighCVSS 8.1Proof of conceptEPSS 2%vtiger · vtiger crmApr 30, 2024
- CVE-2019-500931Monitor
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG fo
HighCVSS 7.2Proof of conceptEPSS 10%vtiger · vtiger crmJan 4, 2019
- CVE-2013-321331Monitor
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1
HighCVSS 7.5Proof of conceptEPSS 3%vtiger · vtiger crmApr 2, 2014
- CVE-2005-381931Monitor
Multiple SQL injection vulnerabilities in vTiger CRM 4.2 and earlier allow remote attackers to inject arbitrary SQL commands and bypass auth
HighCVSS 7.5Proof of conceptEPSS 3%vtiger · vtiger crmNov 25, 2005