CVE-2025-45753: Vtiger CRM

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

Affected products

  • Vtiger Vtiger CRM: version 8.3.0 only

Published 2025-05-21. Last modified 2026-06-17.