VYPR

Suitecrm

by Suitecrm

Source repositories

CVEs (107)

  • CVE-2024-36415CriJun 10, 2024
    risk 0.52cvss 9.1epss 0.01

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2021-25961HigSep 29, 2021
    risk 0.52cvss 8.0epss 0.01

    In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.

  • CVE-2021-25960HigSep 29, 2021
    risk 0.52cvss 8.0epss 0.01

    In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access…

  • CVE-2024-36413HigJun 10, 2024
    risk 0.51cvss 8.9epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2020-15301HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.01

    SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

  • CVE-2015-5946HigAug 7, 2017
    risk 0.51cvss 7.8epss 0.02

    Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

  • CVE-2026-33289HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied…

  • CVE-2026-33288HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails…

  • CVE-2026-29099HigMar 19, 2026
    risk 0.50cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `retrieve()` function in `include/OutboundEmail/OutboundEmail.php` fails to properly neutralize the user controlled `$id` parameter.…

  • CVE-2024-45392HigSep 5, 2024
    risk 0.50cvss 7.7epss 0.00

    SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.

  • CVE-2022-27474HigApr 15, 2022
    risk 0.49cvss 7.2epss 0.23

    SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.

  • CVE-2019-18785HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.

  • CVE-2020-8787HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.

  • CVE-2024-36418HigJun 10, 2024
    risk 0.48cvss 8.5epss 0.01

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6.1 contain a fix for this…

  • CVE-2024-49774HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some syntax constructions. SuiteCRM…

  • CVE-2020-8801HigFeb 13, 2020
    risk 0.47cvss 7.2epss 0.03

    SuiteCRM through 7.11.11 allows PHAR Deserialization.

  • CVE-2026-29189HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and…

  • CVE-2026-29096HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR_Reports module), the `field_function` parameter from POST data is saved directly into the…

  • CVE-2015-5948HigSep 6, 2017
    risk 0.46cvss 8.1epss 0.04

    Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947.

  • CVE-2015-5947HigSep 6, 2017
    risk 0.46cvss 8.1epss 0.03

    SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.

Page 3 of 6