Suitecrm
by Salesagility
Source repositories
CVEs (106)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54787 | Low | 0.24 | 3.7 | 0.00 | Aug 7, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g.… | ||
| CVE-2024-36419 | Med | 0.21 | 4.3 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue. | ||
| CVE-2024-36407 | Low | 0.17 | 3.7 | 0.00 | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the… | ||
| CVE-2023-5350 | Cri | 0.03 | 9.1 | 0.02 | Oct 3, 2023 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-1034 | Hig | 0.02 | 8.8 | 0.28 | Feb 25, 2023 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9. | ||
| CVE-2025-64491 | Med | 0.00 | 6.1 | 0.00 | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering… | ||
| CVE-2025-64489 | Hig | 0.00 | 8.3 | 0.00 | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An… | ||
| CVE-2025-64488 | Hig | 0.00 | 8.8 | 0.00 | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects… | ||
| CVE-2023-47643 | Low | 0.00 | 3.1 | 0.03 | Nov 21, 2023 | SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and… | ||
| CVE-2023-6131 | Hig | 0.00 | 8.8 | 0.01 | Nov 14, 2023 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6130 | Hig | 0.00 | 8.8 | 0.01 | Nov 14, 2023 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6128 | Med | 0.00 | 5.4 | 0.01 | Nov 14, 2023 | Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6127 | Med | 0.00 | 5.4 | 0.00 | Nov 14, 2023 | Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6126 | Cri | 0.00 | 9.8 | 0.01 | Nov 14, 2023 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6125 | Hig | 0.00 | 8.8 | 0.01 | Nov 14, 2023 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | ||
| CVE-2023-6124 | Med | 0.00 | 4.3 | 0.01 | Nov 14, 2023 | Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14. | ||
| CVE-2023-5353 | Med | 0.00 | 6.5 | 0.01 | Oct 3, 2023 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-5351 | Med | 0.00 | 5.4 | 0.00 | Oct 3, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||
| CVE-2023-3627 | Hig | 0.00 | 8.8 | 0.00 | Jul 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | ||
| CVE-2023-3293 | Med | 0.00 | 4.8 | 0.01 | Jun 16, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. |
- risk 0.24cvss 3.7epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g.…
- risk 0.21cvss 4.3epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.
- risk 0.17cvss 3.7epss 0.00
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the…
- risk 0.03cvss 9.1epss 0.02
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.02cvss 8.8epss 0.28
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
- risk 0.00cvss 6.1epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering…
- risk 0.00cvss 8.3epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An…
- risk 0.00cvss 8.8epss 0.00
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects…
- risk 0.00cvss 3.1epss 0.03
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and…
- risk 0.00cvss 8.8epss 0.01
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 8.8epss 0.01
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 5.4epss 0.00
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 9.8epss 0.01
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 8.8epss 0.01
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- risk 0.00cvss 4.3epss 0.01
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
- risk 0.00cvss 6.5epss 0.01
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
- risk 0.00cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
- risk 0.00cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
Page 5 of 6