FAIL › dossier
vtiger
VENDOR· dossier confidence 50%
vTiger CRM is an open-source CRM platform with a critical security posture due to multiple remote code execution vulnerabilities discovered in recent versions, including reflected XSS in version 7.4.0 and authenticated RCE via file upload in version 8.4.0.
PROFILE
CategorySoftware VendorWhat they dovTiger CRM is an open-source CRM platform that provides customer relationship management solutions for businesses.
Websitehttps://www.vtiger.com ↗
SECURITY POSTURE
vTiger CRM has a critical security posture with multiple remote code execution vulnerabilities discovered in recent versions, including reflected XSS in version 7.4.0 and authenticated RCE via file upload in version 8.4.0.
Notable failures
- CVE-2024-44777: Reflected XSS RCE in tag parameter
- CVE-2024-44778: Reflected XSS RCE in parent parameter
- CVE-2024-44779: Reflected XSS RCE in viewname parameter
- CVE-2026-23697: Unrestricted file upload RCE
- CVE-2026-23698: Authenticated RCE via module import file upload
Patterns: Repeated reflected XSS RCEs in index page parameters; Authenticated RCE via file upload mechanisms; Lack of input validation in admin module import features
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-08-29 | CVE-2024-44777 | critical | A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. |
| 2024-08-29 | CVE-2024-44778 | critical | A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. |
| 2024-08-29 | CVE-2024-44779 | critical | A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. |
DOSSIER SOURCES
- Palantir Technologies (PLTR) Company Profile & Description · stockanalysis.com
- CVE-2026-23697 · Vtiger — CVE Brief Analyst Report · cvebrief.com
- CVE-2026-23698— Vtiger CRM 8.4.0 认证远程代码执行漏洞 · cve.imfht.com
- Viatris (VTRS) Company Headquarters - financecharts.com · www.financecharts.com
- Vertiv Holdings Co (VRT) Company Profile & Description · stockanalysis.com
- Stripe, Inc. Global Headquarters and Office Locations | Financial ... · exa.ai
Open questions: Exact founding date and headquarters location · Current version distribution and patching velocity
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:48:09.127537+00:00