Known Vulnerabilities for Vtiger Crm by Vtiger
Listed below are 10 of the newest known vulnerabilities associated with "Vtiger Crm" by "Vtiger".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-23698 json | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature tha... | Not Provided | 2026-07-07 | 2026-07-07 |
| CVE-2026-23697 json | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remot... | Not Provided | 2026-07-07 | 2026-07-07 |
| CVE-2024-44779 json | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows a... | Not Provided | 2024-08-29 | 2026-07-05 |
| CVE-2024-44778 json | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows att... | Not Provided | 2024-08-29 | 2026-07-05 |
| CVE-2024-44777 json | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attack... | Not Provided | 2024-08-29 | 2026-07-05 |
| CVE-2024-44776 json | An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious s... | Not Provided | 2024-08-29 | 2026-07-05 |
| CVE-2023-38891 json | SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQu... | 8.8 - HIGH | 2023-09-14 | 2023-09-20 |
| CVE-2022-38335 json | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules... | 5.4 - MEDIUM | 2022-09-27 | 2022-09-29 |
| CVE-2020-22807 json | An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | 9.8 - CRITICAL | 2021-04-29 | 2021-05-19 |
| CVE-2020-19363 json | Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories. | 6.5 - MEDIUM | 2021-01-20 | 2021-01-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vtiger | Vtiger Crm | 7.2.0 | |||
| Application | Vtiger | Vtiger Crm | 7.1.0 | |||
| Application | Vtiger | Vtiger Crm | 7.1.0 | |||
| Application | Vtiger | Vtiger Crm | 7.1.0 | |||
| Application | Vtiger | Vtiger Crm | 7.1.0 | |||
| Application | Vtiger | Vtiger Crm | 7.1.0 | |||
| Application | Vtiger | Vtiger Crm | 7.0.1 | |||
| Application | Vtiger | Vtiger Crm | 7.0 | |||
| Application | Vtiger | Vtiger Crm | 6.5.0 | |||
| Application | Vtiger | Vtiger Crm | 6.3.0 | |||
| Application | Vtiger | Vtiger Crm | 6.2.0 | |||
| Application | Vtiger | Vtiger Crm | 6.1.0 | |||
| Application | Vtiger | Vtiger Crm | 6.1.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0 | |||
| Application | Vtiger | Vtiger Crm | 6.0 | |||
| Application | Vtiger | Vtiger Crm | 5.4.0 |