CVE-2019-11057: Vtiger CRM

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

Affected products

  • Vtiger Vtiger CRM: up to and including 7.0.1; version 7.1.0 only

Published 2019-05-17. Last modified 2026-06-17.