Skip to main content

Vendor/product archive

salesagility / suitecrm CVEs

Beta · best-effort

105 CVEs tagged to salesagility / suitecrm26 Critical, 41 High, 35 Medium, 3 Low, 0 Unrated.

CVE-2019-25664

Published Apr 5, 2026

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate d…

CVSS 7.1 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2019-25663

Published Apr 5, 2026

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. At…

CVSS 7.1 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-64493

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64492

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnera…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64491

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scri…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64490

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privile…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64489

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64488

Published Nov 8, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1,…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50590

Published Nov 6, 2025

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful ex…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2022-50589

Published Nov 6, 2025

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation all…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-41384

Published Oct 27, 2025

Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to in…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54787

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthen…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54784

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer i…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54783

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vul…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54788

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execu…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54786

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCa…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-54785

Published Aug 7, 2025

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanit…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-45186

Published Jan 7, 2025

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45185

Published Jan 7, 2025

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50335

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50333

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserL…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50332

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteR…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49774

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installa…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49773

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL inject…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49772

Published Nov 5, 2024

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 105 CVEsPage 1 of 5