Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 1.2% | — | Vtiger CRMAI | 7/7/2026 | 8/7/2026 | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the… | |
| Aplazada | Alta (8.7) | 1.00% | — | Vtiger CRMAIApache Http ServerAI | 7/7/2026 | 8/7/2026 | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The… | |
| Aplazada | Media (6.1) | 0.26% | — | Vtiger CRMAI | 13/4/2026 | 17/6/2026 | A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interface. The injected… | |
| Aplazada | Media (5.4) | 0.14% | — | Vtiger CRMAI | 13/4/2026 | 17/6/2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s session. | |
| Analizada | Alta (7.2) | 0.45% | — | Vtiger CRM | 21/5/2025 | 17/6/2026 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature. | |
| Analizada | Media (6.1) | 0.29% | — | Vtiger CRM | 21/5/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user… | |
| Analizada | Media (5.3) | 0.40% | — | Vtiger CRM | 24/2/2025 | 17/6/2026 | A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.20% | — | Master Software Solutions WP Vtiger SynchronizationAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects WP VTiger Synchronization: from n/a through <= 1.1.1. | |
| Analizada | Media (6.1) | 0.36% | — | Vtiger CRM | 10/1/2025 | 17/6/2026 | Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. | |
| Analizada | Media (5.4) | 0.31% | — | Vtiger CRM | 14/10/2024 | 17/6/2026 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. | |
| Modificada | Crítica (9.6) | 0.78% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Crítica (9.6) | 0.73% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Crítica (9.6) | 0.72% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Modificada | Media (6.1) | 0.32% | — | Vtiger CRM | 29/8/2024 | 5/7/2026 | An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. | |
| Analizada | Alta (8.3) | 0.40% | — | Vtiger CRM | 16/8/2024 | 17/6/2026 | VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules. | |
| Analizada | Alta (7.2) | 0.49% | — | Vtiger CRM | 16/8/2024 | 17/6/2026 | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. | |
| Analizada | Alta (8.1) | 1.7% | — | Vtiger CRM | 30/4/2024 | 17/6/2026 | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load). | |
| Modificada | Alta (8.8) | 1.3% | — | Vtiger CRM | 14/9/2023 | 17/6/2026 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php. | |
| Modificada | Media (5.4) | 0.86% | — | Vtiger CRM | 27/9/2022 | 17/6/2026 | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules. | |
| Modificada | Crítica (9.8) | 1.3% | — | Vtiger CRM | 29/4/2021 | 17/6/2026 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | |
| Modificada | Media (6.5) | 3.6% | — | Vtiger CRM | 20/1/2021 | 17/6/2026 | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. | |
| Modificada | Media (6.1) | 0.75% | — | Vtiger CRM | 20/1/2021 | 17/6/2026 | Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | |
| Modificada | Alta (8.8) | 43% | — | Vtiger CRM | 7/2/2020 | 16/6/2026 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 40% | — | Vtiger CRM | 6/2/2020 | 17/6/2026 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a… | |
| Modificada | Crítica (9.8) | 69% | — | Vtiger CRM | 29/1/2020 | 16/6/2026 | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. |