Suitecrm
by Salesagility
Source repositories
CVEs (106)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42840 | Hig | 0.65 | 8.8 | 0.59 | Oct 22, 2021 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP… | ||
| CVE-2020-28328 | Hig | 0.65 | 8.8 | 0.63 | Nov 6, 2020 | SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root. | ||
| CVE-2022-50589 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2025 | SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code. | ||
| CVE-2024-1644 | Cri | 0.64 | 9.9 | 0.01 | Feb 20, 2024 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. | ||
| CVE-2021-45899 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | ||
| CVE-2021-45898 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | ||
| CVE-2020-8786 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4). | ||
| CVE-2020-8785 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4). | ||
| CVE-2020-8784 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4). | ||
| CVE-2020-8783 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2020 | SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4). | ||
| CVE-2020-8803 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list. | ||
| CVE-2020-8802 | Cri | 0.64 | 9.8 | 0.03 | Feb 13, 2020 | SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation. | ||
| CVE-2019-14454 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation. | ||
| CVE-2019-13335 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2019 | SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. | ||
| CVE-2019-12601 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3). | ||
| CVE-2019-12600 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3). | ||
| CVE-2019-12599 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection. | ||
| CVE-2019-12598 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3). | ||
| CVE-2019-6506 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2019 | SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. | ||
| CVE-2022-23940 | Hig | 0.62 | 8.8 | 0.53 | Mar 10, 2022 | SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a… |
- risk 0.65cvss 8.8epss 0.59
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP…
- risk 0.65cvss 8.8epss 0.63
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
- risk 0.64cvss 9.9epss 0.01
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
- risk 0.64cvss 9.8epss 0.03
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
- risk 0.64cvss 9.8epss 0.03
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
- risk 0.64cvss 9.8epss 0.02
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
- risk 0.64cvss 9.8epss 0.01
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
- risk 0.62cvss 8.8epss 0.53
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a…
Page 1 of 6