CVE-2020-10227: Vtenext

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.

Affected products

Published 2020-09-14. Last modified 2026-06-17.