VYPR

Suitecrm

by Salesagility

Source repositories

CVEs (106)

  • CVE-2021-42840HigOct 22, 2021
    risk 0.65cvss 8.8epss 0.59

    SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP…

  • CVE-2020-28328HigNov 6, 2020
    risk 0.65cvss 8.8epss 0.63

    SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

  • CVE-2022-50589CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

  • CVE-2024-1644CriFeb 20, 2024
    risk 0.64cvss 9.9epss 0.01

    Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

  • CVE-2021-45899CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

  • CVE-2021-45898CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

  • CVE-2020-8786CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).

  • CVE-2020-8785CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).

  • CVE-2020-8784CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).

  • CVE-2020-8783CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).

  • CVE-2020-8803CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

  • CVE-2020-8802CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.

  • CVE-2019-14454CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.

  • CVE-2019-13335CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.01

    SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.

  • CVE-2019-12601CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).

  • CVE-2019-12600CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

  • CVE-2019-12599CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

  • CVE-2019-12598CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).

  • CVE-2019-6506CriApr 2, 2019
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.

  • CVE-2022-23940HigMar 10, 2022
    risk 0.62cvss 8.8epss 0.53

    SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a…

Page 1 of 6