VYPR

Vendor CVEs

Suitecrm

All CVEs

107 total · sorted by risk
  • CVE-2025-64491MedNov 8, 2025
    risk 0.00cvss 6.1epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering…

  • CVE-2025-64489HigNov 8, 2025
    risk 0.00cvss 8.3epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An…

  • CVE-2025-64488HigNov 8, 2025
    risk 0.00cvss 8.8epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects…

  • CVE-2023-47643LowNov 21, 2023
    risk 0.00cvss 3.1epss 0.03

    SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and…

  • CVE-2023-6126CriNov 14, 2023
    risk 0.00cvss 9.8epss 0.01

    Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2021-25961HigSep 29, 2021
    risk 0.00cvss 8.0epss 0.01

    In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.

  • CVE-2021-25960HigSep 29, 2021
    risk 0.00cvss 8.0epss 0.01

    In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access…

Page 3 of 3