Vtiger

Vtiger Crm

76 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.07%
  • Veröffentlicht 07.07.2026 16:17:02
  • Zuletzt bearbeitet 08.07.2026 15:28:15

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extensio...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 07.07.2026 16:10:24
  • Zuletzt bearbeitet 08.07.2026 15:28:15

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleMa...

  • EPSS 0.16%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 17.04.2026 15:33:34

A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to injec...

  • EPSS 0.14%
  • Veröffentlicht 13.04.2026 00:00:00
  • Zuletzt bearbeitet 17.04.2026 15:33:34

Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and e...

  • EPSS 0.42%
  • Veröffentlicht 21.05.2025 00:00:00
  • Zuletzt bearbeitet 10.06.2025 19:34:41

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

  • EPSS 0.27%
  • Veröffentlicht 21.05.2025 00:00:00
  • Zuletzt bearbeitet 10.06.2025 19:34:54

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. Wh...

  • EPSS 0.39%
  • Veröffentlicht 24.02.2025 05:15:10
  • Zuletzt bearbeitet 29.01.2026 02:11:45

A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The atta...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 10.01.2025 18:15:22
  • Zuletzt bearbeitet 17.04.2025 02:38:37

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.10.2024 14:15:11
  • Zuletzt bearbeitet 30.10.2024 14:32:43

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

  • EPSS 0.78%
  • Veröffentlicht 29.08.2024 18:15:14
  • Zuletzt bearbeitet 05.07.2026 01:20:28

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.