Vtiger develops a customer relationship management platform that, despite a focused product portfolio, sits in the request path of business-critical customer data and communications, making its security posture material to a broad user base. The vendor's disclosures concentrate in its core CRM product and recur through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file upload—all characteristic of web-facing business software where input validation and access control are central to data integrity and confidentiality. Vulnerabilities affecting the vendor frequently acquire public exploit code, elevating the practical risk to organizations running unpatched instances. Defenders should treat Vtiger advisories as requiring timely attention, especially for internet-exposed deployments, and maintain current patch levels; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vtiger over time
Signals from CVEs in this vendor scope (74 CVEs).
74 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-3214CRITICAL vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. | Jan 28, 2020 | 9.8 | 88 | NO | YES |
CVE-2013-3215CRITICAL vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function. | Jan 29, 2020 | 9.8 | 79 | NO | YES |
CVE-2013-3591HIGH vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | Feb 7, 2020 | 8.8 | 64 | NO | YES |
CVE-2015-6000HIGH Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earl | Feb 6, 2020 | 8.8 | 64 | NO | YES |
CVE-2014-2268MEDIUM views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a req | Nov 16, 2014 | 5.0 | 52 | NO | YES |
CVE-2016-1713HIGH Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows r | Apr 14, 2017 | 7.3 | 51 | NO | YES |
CVE-2019-5009HIGH Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can p | Jan 4, 2019 | 7.2 | 39 | NO | YES |
CVE-2009-3249HIGH Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter | Sep 18, 2009 | 7.5 | 39 | NO | YES |
CVE-2026-23697HIGH Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing a | Jul 7, 2026 | 8.8 | 38 | NO | NO |
CVE-2009-3250HIGH The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail messag | Sep 18, 2009 | 9.0 | 37 | NO | YES |
Signals from CVEs in this vendor scope (74 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vtiger.
Media articles that mention a CVE ID that affects a product developed by Vtiger — matched by CVE ID, not by vendor name.