Skip to content
COOEY

FAIL › dossier

vtiger crm

PRODUCT

· dossier confidence 50%

vTiger CRM is an open-source CRM platform with a recent critical security posture due to three independent reflected XSS vulnerabilities in version 7.4.0 that enable remote code execution.

PROFILE
CategorySoftwareWhat they dovTiger CRM is an open-source customer relationship management (CRM) solution providing tools for managing contacts, leads, and sales pipelines. Websitehttps://www.vtiger.com ↗
SECURITY POSTURE

Recent critical vulnerabilities in vTiger CRM 7.4.0 allow remote code execution via reflected XSS in tag, parent, and viewname parameters on the index page.

Notable failures
  • CVE-2024-44777: Reflected XSS RCE in tag parameter
  • CVE-2024-44778: Reflected XSS RCE in parent parameter
  • CVE-2024-44779: Reflected XSS RCE in viewname parameter
Patterns: Multiple reflected XSS RCEs in index page parameters
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-08-29 CVE-2024-44777 critical A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29 CVE-2024-44778 critical A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
2024-08-29 CVE-2024-44779 critical A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
Open questions: vTiger CRM version 7.4.0 patch status · vTiger CRM adoption rate in defense-industrial-base (DIB) environments
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:53:03.704974+00:00