Vulnerabilities > Vtiger

DATE CVE VULNERABILITY TITLE RISK
2024-10-14 CVE-2024-48119 Cross-site Scripting vulnerability in Vtiger CRM 8.2.0
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter.
network
low complexity
vtiger CWE-79
5.4
2024-08-29 CVE-2024-44776 Open Redirect vulnerability in Vtiger CRM 7.4.0
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
network
low complexity
vtiger CWE-601
6.1
2024-08-29 CVE-2024-44777 Cross-site Scripting vulnerability in Vtiger CRM 7.4.0
A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
network
low complexity
vtiger CWE-79
critical
9.6
2024-08-29 CVE-2024-44778 Cross-site Scripting vulnerability in Vtiger CRM 7.4.0
A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
network
low complexity
vtiger CWE-79
critical
9.6
2024-08-29 CVE-2024-44779 Cross-site Scripting vulnerability in Vtiger CRM 7.4.0
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
network
low complexity
vtiger CWE-79
critical
9.6
2023-09-14 CVE-2023-38891 SQL Injection vulnerability in Vtiger CRM 7.5.0
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
network
low complexity
vtiger CWE-89
8.8
2022-09-27 CVE-2022-38335 Cross-site Scripting vulnerability in Vtiger CRM
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
network
low complexity
vtiger CWE-79
5.4
2021-04-29 CVE-2020-22807 SQL Injection vulnerability in Vtiger CRM 7.2.0
An issue was dicovered in vtiger crm 7.2.
network
low complexity
vtiger CWE-89
critical
9.8
2021-01-20 CVE-2020-19363 Information Exposure vulnerability in Vtiger CRM 7.2.0
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
network
low complexity
vtiger CWE-200
6.5
2021-01-20 CVE-2020-19362 Cross-site Scripting vulnerability in Vtiger CRM 7.2.0
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
network
low complexity
vtiger CWE-79
6.1