VYPR

Suitecrm

by Suitecrm

Source repositories

CVEs (107)

  • CVE-2021-31792MedApr 30, 2021
    risk 0.35cvss 5.4epss 0.01

    XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field

  • CVE-2020-14208MedNov 18, 2020
    risk 0.35cvss 5.4epss 0.01

    SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.

  • CVE-2022-50590MedNov 6, 2025
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including…

  • CVE-2025-54786MedAug 7, 2025
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any…

  • CVE-2024-49773MedNov 5, 2024
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_post` parameter in `export`…

  • CVE-2023-6388MedFeb 7, 2024
    risk 0.33cvss 5.0epss 0.00

    Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

  • CVE-2024-50335MedNov 5, 2024
    risk 0.32cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious JavaScript code. This…

  • CVE-2026-29106MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is…

  • CVE-2024-36417MedJun 10, 2024
    risk 0.30cvss 5.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, which could allow for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this…

  • CVE-2026-29105MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter…

  • CVE-2024-36406MedJun 10, 2024
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2019-18782MedMar 20, 2020
    risk 0.28cvss 5.3epss 0.01

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.

  • CVE-2019-16922MedSep 27, 2019
    risk 0.28cvss 5.3epss 0.01

    SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.

  • CVE-2026-29107MedMar 19, 2026
    risk 0.26cvss 5.0epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `` tags. When a PDF is exported using this template, the content (for example, `<img…

  • CVE-2026-29101MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

  • CVE-2026-29098MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `action_exportCustom` function in `modules/ModuleBuilder/controller.php` fails to properly neutralize path traversal sequences in the…

  • CVE-2025-54787LowAug 7, 2025
    risk 0.24cvss 3.7epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g.…

  • CVE-2024-36419MedJun 10, 2024
    risk 0.21cvss 4.3epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.

  • CVE-2024-36407LowJun 10, 2024
    risk 0.17cvss 3.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the…

  • CVE-2026-29104LowMar 19, 2026
    risk 0.11cvss 2.7epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can…

Page 5 of 6