VYPR

Vendor CVEs

Suitecrm

All CVEs

107 total · sorted by risk
  • CVE-2021-42840HigOct 22, 2021
    risk 0.65cvss 8.8epss 0.59

    SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP…

  • CVE-2020-28328HigNov 6, 2020
    risk 0.65cvss 8.8epss 0.63

    SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.

  • CVE-2022-50589CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

  • CVE-2024-1644CriFeb 20, 2024
    risk 0.64cvss 9.9epss 0.01

    Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

  • CVE-2021-45899CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

  • CVE-2021-45898CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

  • CVE-2020-8786CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).

  • CVE-2020-8785CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).

  • CVE-2020-8784CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).

  • CVE-2020-8783CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).

  • CVE-2020-8803CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

  • CVE-2020-8802CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.

  • CVE-2019-14454CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.

  • CVE-2019-12601CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).

  • CVE-2019-12600CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

  • CVE-2019-12599CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

  • CVE-2019-12598CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).

  • CVE-2019-6506CriApr 2, 2019
    risk 0.64cvss 9.8epss 0.02

    SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.

  • CVE-2022-23940HigMar 10, 2022
    risk 0.62cvss 8.8epss 0.53

    SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a…

  • CVE-2024-36412CriJun 10, 2024
    risk 0.58cvss 10.0epss 0.06

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2021-45897HigJan 28, 2022
    risk 0.58cvss 8.8epss 0.05

    SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

  • CVE-2025-64492HigNov 8, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by…

  • CVE-2025-54788HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching…

  • CVE-2025-54785HigAug 7, 2025
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege…

  • CVE-2022-45185HigJan 7, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.

  • CVE-2024-50332HigNov 5, 2024
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been addressed in versions 7.14.6 and 8.7.1. Users are advised to…

  • CVE-2024-49772HigNov 5, 2024
    risk 0.57cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack. Authenticated user with low pivilege can leak all data in database.…

  • CVE-2021-41597HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

  • CVE-2021-45041HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

  • CVE-2021-41869HigOct 4, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.

  • CVE-2020-8800HigFeb 13, 2020
    risk 0.57cvss 8.8epss 0.03

    SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.

  • CVE-2019-18784CriNov 6, 2019
    risk 0.57cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.

  • CVE-2024-36416HigJun 10, 2024
    risk 0.56cvss 8.6epss 0.02

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive data. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36411CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36410CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36409CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36408CriJun 10, 2024
    risk 0.55cvss 9.6epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2025-64490HigNov 8, 2025
    risk 0.54cvss 8.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and…

  • CVE-2022-45186HigJan 7, 2025
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

  • CVE-2026-29103CriMar 19, 2026
    risk 0.52cvss 9.1epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This…

  • CVE-2024-36415CriJun 10, 2024
    risk 0.52cvss 9.1epss 0.01

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-36413HigJun 10, 2024
    risk 0.51cvss 8.9epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2020-15301HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.01

    SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

  • CVE-2015-5946HigAug 7, 2017
    risk 0.51cvss 7.8epss 0.02

    Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

  • CVE-2026-33289HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied…

  • CVE-2026-33288HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails…

  • CVE-2026-29099HigMar 19, 2026
    risk 0.50cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `retrieve()` function in `include/OutboundEmail/OutboundEmail.php` fails to properly neutralize the user controlled `$id` parameter.…

  • CVE-2024-45392HigSep 5, 2024
    risk 0.50cvss 7.7epss 0.00

    SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch for the issue.

  • CVE-2022-27474HigApr 15, 2022
    risk 0.49cvss 7.2epss 0.23

    SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.

  • CVE-2019-18785HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.

Page 1 of 3