Vtiger
Vtiger CRM: vulnerabilidades y CVE
Vtiger CRM tiene 75 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses3
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-23698 | Alta (8.6) | 1.2% | — | 7 jul 2026 | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted… |
| CVE-2026-26460 | Media (6.1) | 0.26% | — | 13 abr 2026 | A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents… |
| CVE-2025-70936 | Media (5.4) | 0.14% | — | 13 abr 2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double… |
| CVE-2025-45753 | Alta (7.2) | 0.45% | — | 21 may 2025 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature. |
| CVE-2025-45755 | Media (6.1) | 0.29% | — | 21 may 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload,… |
| CVE-2025-1618 | Media (5.3) | 0.40% | — | 24 feb 2025 | A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to… |
| CVE-2024-54687 | Media (6.1) | 0.36% | — | 10 ene 2025 | Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. |
| CVE-2024-48119 | Media (5.4) | 0.31% | — | 14 oct 2024 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. |
| CVE-2024-44779 | Crítica (9.6) | 0.78% | — | 29 ago 2024 | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted… |
| CVE-2024-44778 | Crítica (9.6) | 0.73% | — | 29 ago 2024 | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted… |
| CVE-2024-44777 | Crítica (9.6) | 0.72% | — | 29 ago 2024 | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted… |
| CVE-2024-44776 | Media (6.1) | 0.32% | — | 29 ago 2024 | An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. |
| CVE-2024-42995 | Alta (8.3) | 0.40% | — | 16 ago 2024 | VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules. |
| CVE-2024-42994 | Alta (7.2) | 0.49% | — | 16 ago 2024 | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. |
| CVE-2023-46304 | Alta (8.1) | 1.7% | — | 30 abr 2024 | modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on… |
| CVE-2023-38891 | Alta (8.8) | 1.3% | — | 14 sept 2023 | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php. |
| CVE-2022-38335 | Media (5.4) | 0.86% | — | 27 sept 2022 | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules. |
| CVE-2020-22807 | Crítica (9.8) | 1.3% | — | 29 abr 2021 | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. |
| CVE-2020-19363 | Media (6.5) | 3.6% | — | 20 ene 2021 | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. |
| CVE-2020-19362 | Media (6.1) | 0.75% | — | 20 ene 2021 | Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. |
| CVE-2013-3591 | Alta (8.8) | 43% | — | 7 feb 2020 | vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability |
| CVE-2015-6000 | Alta (8.8) | 40% | — | 6 feb 2020 | Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users… |
| CVE-2013-3215 | Crítica (9.8) | 69% | — | 29 ene 2020 | vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. |
| CVE-2013-3214 | Crítica (9.8) | 85% | — | 28 ene 2020 | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. |
| CVE-2013-3212 | Alta (8.1) | 7.5% | — | 28 ene 2020 | vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code. |
| CVE-2019-19202 | Alta (8.8) | 1.0% | — | 21 nov 2019 | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. |
| CVE-2018-8047 | Media (6.1) | 1.3% | — | 6 jun 2019 | vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject… |
| CVE-2016-10754 | Alta (8.8) | 1.4% | — | 24 may 2019 | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter. |
| CVE-2019-11057 | Alta (8.8) | 1.2% | — | 17 may 2019 | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands. |
| CVE-2019-5009 | Alta (7.2) | 9.9% | — | 4 ene 2019 | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.