CVE-2026-29107
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with <img> tags. When a PDF is exported using this template, the content (for example, <img src=http://{burp_collaborator_url}> is rendered server side, and thus a request is issued from the server, resulting in Server-Side Request Forgery.
Versions 7.15.1 and 8.9.3 patch the issue.
MEDIUM · CVSS 5
EPSS 0.00044
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0