Yetiforce is a customer relationship management platform that, despite a narrow product footprint, occupies a prominent position in the vulnerability landscape among CRM and business-application software. Its vulnerability profile concentrates around web-application input handling and request validation, with recurring weakness classes including cross-site scripting, cross-site request forgery, improper input validation, and path traversal that reflect typical risks in server-side web applications managing user data and file access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yetiforce over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4121MEDIUM yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Dec 16, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-4107MEDIUM yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Dec 14, 2021 | 6.1 | 22 | NO | NO |
CVE-2022-3005MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | Sep 20, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-3004MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | Sep 20, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-2829MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | Aug 23, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-1411MEDIUM Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data fro | May 5, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-4116MEDIUM yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Dec 15, 2021 | 5.4 | 21 | NO | NO |
CVE-2022-3000MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. | Sep 20, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-0269HIGH Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. | Jan 24, 2022 | 8.0 | 20 | NO | NO |
CVE-2023-49508MEDIUM Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license | Feb 16, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yetiforce.
Media articles that mention a CVE ID that affects a product developed by Yetiforce — matched by CVE ID, not by vendor name.