Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vtiger

First CVE: Nov 26, 2005Active for: 21 yearsTotal CVEs: 74
49.9
VTI Score
TOP TARGET

Vtiger develops a customer relationship management platform that, despite a focused product portfolio, sits in the request path of business-critical customer data and communications, making its security posture material to a broad user base. The vendor's disclosures concentrate in its core CRM product and recur through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file upload—all characteristic of web-facing business software where input validation and access control are central to data integrity and confidentiality. Vulnerabilities affecting the vendor frequently acquire public exploit code, elevating the practical risk to organizations running unpatched instances. Defenders should treat Vtiger advisories as requiring timely attention, especially for internet-exposed deployments, and maintain current patch levels; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
74
Total CVEs
More Total CVEs than 99% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vtiger over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 26, 2005
20 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (74 CVEs).

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-3214CRITICAL
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
Jan 28, 20209.888NOYES
CVE-2013-3215CRITICAL
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
Jan 29, 20209.879NOYES
CVE-2013-3591HIGH
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Feb 7, 20208.864NOYES
CVE-2015-6000HIGH
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earl
Feb 6, 20208.864NOYES
CVE-2014-2268MEDIUM
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a req
Nov 16, 20145.052NOYES
CVE-2016-1713HIGH
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows r
Apr 14, 20177.351NOYES
CVE-2019-5009HIGH
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can p
Jan 4, 20197.239NOYES
CVE-2009-3249HIGH
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter
Sep 18, 20097.539NOYES
CVE-2026-23697HIGH
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing a
Jul 7, 20268.838NONO
CVE-2009-3250HIGH
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail messag
Sep 18, 20099.037NOYES
View all 74 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products74 CVEs
51%
38%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network30 (40.5%)
Unknown43 (58.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (39.2%)
High2 (2.7%)
Unknown43 (58.1%)
User Interaction
None18 (24.3%)
Unknown43 (58.1%)
Required13 (17.6%)
Privileges Required
Low12 (16.2%)
High4 (5.4%)
None15 (20.3%)
Unknown43 (58.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (74 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
8.1% of CVEs· 98th percentile
Nuclei
1 CVE
1.4% of CVEs· 95th percentile
ExploitDB
22 CVEs
29.7% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vtiger.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vtiger — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vtiger's Products

View all 5 CNAs →

Top CWEs