VYPR

Suitecrm

by Salesagility

Source repositories

CVEs (106)

  • CVE-2025-54787LowAug 7, 2025
    risk 0.24cvss 3.7epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g.…

  • CVE-2024-36419MedJun 10, 2024
    risk 0.21cvss 4.3epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.

  • CVE-2024-36407LowJun 10, 2024
    risk 0.17cvss 3.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the…

  • CVE-2023-5350CriOct 3, 2023
    risk 0.03cvss 9.1epss 0.02

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-1034HigFeb 25, 2023
    risk 0.02cvss 8.8epss 0.28

    Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

  • CVE-2025-64491MedNov 8, 2025
    risk 0.00cvss 6.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering…

  • CVE-2025-64489HigNov 8, 2025
    risk 0.00cvss 8.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An…

  • CVE-2025-64488HigNov 8, 2025
    risk 0.00cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects…

  • CVE-2023-47643LowNov 21, 2023
    risk 0.00cvss 3.1epss 0.03

    SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and…

  • CVE-2023-6131HigNov 14, 2023
    risk 0.00cvss 8.8epss 0.01

    Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6130HigNov 14, 2023
    risk 0.00cvss 8.8epss 0.01

    Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6128MedNov 14, 2023
    risk 0.00cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6127MedNov 14, 2023
    risk 0.00cvss 5.4epss 0.00

    Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6126CriNov 14, 2023
    risk 0.00cvss 9.8epss 0.01

    Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6125HigNov 14, 2023
    risk 0.00cvss 8.8epss 0.01

    Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-6124MedNov 14, 2023
    risk 0.00cvss 4.3epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.

  • CVE-2023-5353MedOct 3, 2023
    risk 0.00cvss 6.5epss 0.01

    Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-5351MedOct 3, 2023
    risk 0.00cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2023-3627HigJul 11, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.

  • CVE-2023-3293MedJun 16, 2023
    risk 0.00cvss 4.8epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.

Page 5 of 6