VendorsVtigervtiger_crmany version
Vulnerabilities

Vtiger vtiger CRM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2007-3617
The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.
Published 2007-07-06 · Modified
4.0EPSS 0.010
CVE-2009-3257
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.
Published 2009-09-18 · Modified
3.6EPSS 0.009
CVE-2007-3601
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.
Published 2007-07-06 · Modified
2.1EPSS 0.008
← Prev2 / 2