VYPR

Suitecrm

by Salesagility

Source repositories

CVEs (106)

  • CVE-2024-36412CriJun 10, 2024
    risk 0.58cvss 10.0epss 0.06

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2021-45897HigJan 28, 2022
    risk 0.58cvss 8.8epss 0.05

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

  • CVE-2025-64492HigNov 8, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by…

  • CVE-2025-54788HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching…

  • CVE-2025-54785HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege…

  • CVE-2022-45185HigJan 7, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

  • CVE-2024-50332HigNov 5, 2024
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1. Users are advised to…

  • CVE-2024-49772HigNov 5, 2024
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can leak all data in database.…

  • CVE-2021-41597HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

  • CVE-2021-45041HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

  • CVE-2021-41869HigOct 4, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.

  • CVE-2020-8800HigFeb 13, 2020
    risk 0.57cvss 8.8epss 0.03

    SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.

  • CVE-2019-18784CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.

  • CVE-2024-36416HigJun 10, 2024
    risk 0.56cvss 8.6epss 0.02

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36411CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36410CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36409CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36408CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2025-64490HigNov 8, 2025
    risk 0.54cvss 8.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and…

  • CVE-2022-45186HigJan 7, 2025
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

Page 2 of 6