VYPR

Vendor CVEs

Suitecrm

All CVEs

107 total · sorted by risk
  • CVE-2020-8787HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.

  • CVE-2024-36418HigJun 10, 2024
    risk 0.48cvss 8.5epss 0.01

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution attack. Versions 7.14.4 and 8.6.1 contain a fix for this…

  • CVE-2024-49774HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks can be bypassed with some syntax constructions. SuiteCRM…

  • CVE-2020-8801HigFeb 13, 2020
    risk 0.47cvss 7.2epss 0.03

    SuiteCRM through 7.11.11 allows PHAR Deserialization.

  • CVE-2026-29189HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and…

  • CVE-2026-29096HigMar 19, 2026
    risk 0.46cvss 8.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR_Reports module), the `field_function` parameter from POST data is saved directly into the…

  • CVE-2015-5948HigSep 6, 2017
    risk 0.46cvss 8.1epss 0.04

    Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947.

  • CVE-2015-5947HigSep 6, 2017
    risk 0.46cvss 8.1epss 0.03

    SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.

  • CVE-2024-50333MedNov 5, 2024
    risk 0.43cvss 6.6epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function can be used to write attacker-controlled data into the custom language…

  • CVE-2024-36414HigJun 10, 2024
    risk 0.43cvss 7.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the connectors file verification allows for a server-side request forgery attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2026-29097HigMar 19, 2026
    risk 0.42cvss 7.5epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1 and 8.9.3 contain a Server-Side Request Forgery (SSRF) vulnerability combined with a Denial of Service (DoS) condition in the RSS Feed Dashlet…

  • CVE-2025-64493MedNov 8, 2025
    risk 0.42cvss 6.5epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of…

  • CVE-2020-8804MedFeb 13, 2020
    risk 0.42cvss 6.5epss 0.01

    SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.

  • CVE-2026-29109HigMar 20, 2026
    risk 0.40cvss 7.2epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator…

  • CVE-2026-29102HigMar 19, 2026
    risk 0.40cvss 7.2epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

  • CVE-2025-41384MedOct 27, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript code at the end. The server will attempt to…

  • CVE-2025-54784MedAug 7, 2025
    risk 0.40cvss 6.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of…

  • CVE-2025-54783MedAug 7, 2025
    risk 0.40cvss 6.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP…

  • CVE-2021-45903MedDec 28, 2021
    risk 0.40cvss 6.1epss 0.01

    A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.

  • CVE-2021-39268MedAug 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.

  • CVE-2021-39267MedAug 18, 2021
    risk 0.40cvss 6.1epss 0.02

    Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow…

  • CVE-2020-15300MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.

  • CVE-2019-14752MedSep 30, 2019
    risk 0.40cvss 6.1epss 0.01

    SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.

  • CVE-2019-25664HigApr 5, 2026
    risk 0.39cvss 7.1epss 0.00

    SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the…

  • CVE-2019-25663HigApr 5, 2026
    risk 0.39cvss 7.1epss 0.00

    SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using…

  • CVE-2026-29100HigMar 19, 2026
    risk 0.39cvss 7.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML injection vulnerability in the login page that allows attackers to inject arbitrary HTML content, enabling phishing attacks and…

  • CVE-2026-32697MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler::getRecord()` method retrieves any record by module and ID without checking the current user's ACL view permission. The companion…

  • CVE-2026-29108MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and…

  • CVE-2021-41596MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.02

    SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.

  • CVE-2021-41595MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.02

    SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.

  • CVE-2021-31792MedApr 30, 2021
    risk 0.35cvss 5.4epss 0.01

    XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field

  • CVE-2020-14208MedNov 18, 2020
    risk 0.35cvss 5.4epss 0.01

    SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.

  • CVE-2022-50590MedNov 6, 2025
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including…

  • CVE-2025-54786MedAug 7, 2025
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any…

  • CVE-2024-49773MedNov 5, 2024
    risk 0.34cvss 5.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is used to build SQL query. `current_post` parameter in `export`…

  • CVE-2023-6388MedFeb 7, 2024
    risk 0.33cvss 5.0epss 0.00

    Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

  • CVE-2024-50335MedNov 5, 2024
    risk 0.32cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious JavaScript code. This…

  • CVE-2026-29106MedMar 19, 2026
    risk 0.31cvss 5.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is…

  • CVE-2024-36417MedJun 10, 2024
    risk 0.30cvss 5.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, which could allow for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this…

  • CVE-2026-29105MedMar 19, 2026
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter…

  • CVE-2024-36406MedJun 10, 2024
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2019-18782MedMar 20, 2020
    risk 0.28cvss 5.3epss 0.01

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.

  • CVE-2019-16922MedSep 27, 2019
    risk 0.28cvss 5.3epss 0.01

    SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.

  • CVE-2026-29107MedMar 19, 2026
    risk 0.26cvss 5.0epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `` tags. When a PDF is exported using this template, the content (for example, `<img…

  • CVE-2026-29101MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

  • CVE-2026-29098MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `action_exportCustom` function in `modules/ModuleBuilder/controller.php` fails to properly neutralize path traversal sequences in the…

  • CVE-2025-54787LowAug 7, 2025
    risk 0.24cvss 3.7epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is named by an ID (e.g.…

  • CVE-2024-36419MedJun 10, 2024
    risk 0.21cvss 4.3epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version 8.6.1 contains a patch for the issue.

  • CVE-2024-36407LowJun 10, 2024
    risk 0.17cvss 3.7epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the…

  • CVE-2026-29104LowMar 19, 2026
    risk 0.11cvss 2.7epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can…