Vtiger

Vtiger Crm

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 17.04.2026 15:33:34

A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to injec...

  • EPSS 0.03%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 17.04.2026 15:33:34

Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and e...

  • EPSS 0.4%
  • Veröffentlicht 21.05.2025 00:00:00
  • Zuletzt bearbeitet 10.06.2025 19:34:41

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

  • EPSS 0.23%
  • Veröffentlicht 21.05.2025 00:00:00
  • Zuletzt bearbeitet 10.06.2025 19:34:54

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. Wh...

  • EPSS 0.19%
  • Veröffentlicht 24.02.2025 05:15:10
  • Zuletzt bearbeitet 29.01.2026 02:11:45

A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The atta...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 10.01.2025 18:15:22
  • Zuletzt bearbeitet 17.04.2025 02:38:37

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 14.10.2024 14:15:11
  • Zuletzt bearbeitet 30.10.2024 14:32:43

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

  • EPSS 0.75%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 03.09.2024 18:34:36

A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

  • EPSS 0.39%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 25.03.2025 17:16:09

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

  • EPSS 0.57%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 03.09.2024 18:33:38

A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.