Home/Product/salesagility suitecrm
Product

salesagility suitecrm

124 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-25664
<= 7.10.7
SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action th
7.1HIGH
CVE-2019-25663
<= 7.10.7
SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injec
7.1HIGH
CVE-2026-33289
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
8.8HIGH
CVE-2026-33288
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
8.8HIGH
CVE-2026-32697
< 8.9.3
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3,
6.5MEDIUM
CVE-2026-29189
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
8.1HIGH
CVE-2026-29109
< 8.9.3
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and inclu
7.2HIGH
CVE-2026-29108
< 8.9.3
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3,
6.5MEDIUM
CVE-2026-29107
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
5.0MEDIUM
CVE-2026-29106
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
5.9MEDIUM
CVE-2026-29105
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
5.4MEDIUM
CVE-2026-29104
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
2.7LOW
CVE-2026-29103
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code E
9.1CRITICAL
CVE-2026-29102
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
7.2HIGH
CVE-2026-29101
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
4.9MEDIUM
CVE-2026-29100
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains
7.1HIGH
CVE-2026-29099
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
8.8HIGH
CVE-2026-29098
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
4.9MEDIUM
CVE-2026-29097
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1
7.5HIGH
CVE-2026-29096
< 7.15.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1
8.1HIGH
CVE-2025-64493
>= 8.6.0 and < 8.9.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 throug
6.5MEDIUM
CVE-2025-64492
>= 8.0.0 and < 8.9.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below
8.8HIGH
CVE-2025-64491
< 7.14.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and belo
6.1MEDIUM
CVE-2025-64490
< 7.14.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prio
8.3HIGH
CVE-2025-64489
< 7.14.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prio
8.3HIGH
CVE-2025-64488
< 7.14.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and b
8.8HIGH
CVE-2022-50590
< 7.12.6
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter with
5.3MEDIUM
CVE-2022-50589
< 7.12.6
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within t
9.8CRITICAL
CVE-2025-41384
all versions
Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScrip
6.1MEDIUM
CVE-2025-54787
>= 8.6.0 and < 8.8.1
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability
3.7LOW
CVE-2025-54784
>= 7.14.0 and < 7.14.7
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Sc
6.1MEDIUM
CVE-2025-54783
< 7.14.7
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and belo
6.1MEDIUM
CVE-2025-54788
< 7.14.7
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, t
8.8HIGH
CVE-2025-54786
all versions
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8
5.3MEDIUM
CVE-2025-54785
all versions
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and
8.8HIGH
CVE-2022-45186
all versions
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
8.1HIGH
CVE-2022-45185
all versions
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserializa
8.8HIGH
CVE-2024-50335
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field
4.9MEDIUM
CVE-2024-50333
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not valida
6.6MEDIUM
CVE-2024-50332
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value
8.8HIGH
CVE-2024-49774
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the b
7.2HIGH
CVE-2024-49773
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in
5.3MEDIUM
CVE-2024-49772
< 7.14.6
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.1
8.8HIGH
CVE-2024-45392
< 7.14.5
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access c
7.7HIGH
CVE-2024-36419
< 8.6.1
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1
4.3MEDIUM
CVE-2024-36418
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vuln
8.5HIGH
CVE-2024-36417
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unv
5.7MEDIUM
CVE-2024-36416
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a depr
8.6HIGH
CVE-2024-36415
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vuln
9.1CRITICAL
CVE-2024-36414
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vuln
7.7HIGH
CVE-2024-36413
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vuln
8.9HIGH
CVE-2024-36412
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vuln
10.0CRITICAL
CVE-2024-36411
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poo
9.6CRITICAL
CVE-2024-36410
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poo
9.6CRITICAL
CVE-2024-36409
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poo
9.6CRITICAL
CVE-2024-36408
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poo
9.6CRITICAL
CVE-2024-36407
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a u
3.7LOW
CVE-2024-36406
< 7.14.4
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unc
5.4MEDIUM
CVE-2024-1644
all versions
Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.
9.9CRITICAL
CVE-2023-6388
all versions
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the applic
5.0MEDIUM
CVE-2023-47643
all versions
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enable
3.1LOW
CVE-2023-6131
< 7.12.14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
8.8HIGH
CVE-2023-6130
< 7.12.14
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
8.8HIGH
CVE-2023-6128
< 7.12.14
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
5.4MEDIUM
CVE-2023-6127
< 7.12.14
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
5.4MEDIUM
CVE-2023-6126
< 7.12.14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
9.8CRITICAL
CVE-2023-6125
< 7.12.14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
8.8HIGH
CVE-2023-6124
< 7.12.14
Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.
4.3MEDIUM
CVE-2023-5353
< 7.14.1
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
6.5MEDIUM
CVE-2023-5351
< 7.14.1
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
5.4MEDIUM
CVE-2023-5350
< 7.14.1
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
9.1CRITICAL
CVE-2023-3627
< 8.3.1
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
8.8HIGH
CVE-2023-3293
>= 8.0.0 and < 8.0.3
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
4.8MEDIUM
CVE-2023-1034
< 7.12.9
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
8.8HIGH
CVE-2022-27474
all versions
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
7.2HIGH
CVE-2022-23940
< 7.12.5
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Repor
8.8HIGH
CVE-2022-0756
< 7.12.5
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
6.5MEDIUM
CVE-2022-0755
< 7.12.5
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
4.3MEDIUM
CVE-2022-0754
< 7.12.5
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
6.5MEDIUM
CVE-2021-45899
< 7.12.3
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
9.8CRITICAL
CVE-2021-45898
< 7.12.3
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
9.8CRITICAL
CVE-2021-45897
< 7.12.3
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
8.8HIGH
CVE-2021-41597
>= 7.10.0 and < 7.10.35
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PH
8.8HIGH
CVE-2021-45903
< 7.10.35
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2
6.1MEDIUM
CVE-2021-45041
< 7.12.2
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, invo
8.8HIGH
CVE-2021-42840
< 7.11.19
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances invol
8.8HIGH
CVE-2021-41596
< 7.10.33
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbit
5.3MEDIUM
CVE-2021-41595
< 7.10.33
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbit
5.3MEDIUM
CVE-2021-41869
>= 7.10.0 and < 7.10.33
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
8.8HIGH
CVE-2021-25961
>= 7.1.7 and < 7.10.32
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset
8.0HIGH
CVE-2021-25960
>= 7.10.29 and < 7.10.32
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnera
8.0HIGH
CVE-2021-39268
< 7.11.19
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitr
6.1MEDIUM
CVE-2021-39267
< 7.11.19
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitr
6.1MEDIUM
CVE-2021-31792
< 7.11.19
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
5.4MEDIUM
CVE-2020-15300
<= 7.11.13
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
6.1MEDIUM
CVE-2020-14208
<= 7.11.13
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could
5.4MEDIUM
CVE-2020-15301
<= 7.11.13
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules.
7.8HIGH
CVE-2020-28328
< 7.11.17
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumsta
8.8HIGH
CVE-2019-18785
>= 7.10.0 and < 7.10.21
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
7.5HIGH
CVE-2019-18782
>= 7.10.0 and < 7.10.21
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
5.3MEDIUM
CVE-2020-8787
>= 7.10.0 and < 7.10.23
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
7.5HIGH
CVE-2020-8786
>= 7.10.0 and < 7.10.23
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
9.8CRITICAL
CVE-2020-8785
>= 7.10.0 and < 7.10.23
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
9.8CRITICAL
CVE-2020-8784
>= 7.10.0 and < 7.10.23
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
9.8CRITICAL
CVE-2020-8783
>= 7.10.0 and < 7.10.23
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
9.8CRITICAL
CVE-2020-8804
<= 7.11.10
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
6.5MEDIUM
CVE-2020-8803
<= 7.11.11
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
9.8CRITICAL
CVE-2020-8802
<= 7.11.11
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
9.8CRITICAL
CVE-2020-8801
<= 7.11.11
SuiteCRM through 7.11.11 allows PHAR Deserialization.
7.2HIGH
CVE-2020-8800
<= 7.11.11
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
8.8HIGH
CVE-2019-18784
>= 7.10.0 and < 7.10.21
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
9.8CRITICAL
CVE-2019-14454
>= 7.10.0 and < 7.10.20
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
9.8CRITICAL
CVE-2019-13335
>= 7.10.0 and < 7.10.19
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
9.8CRITICAL
CVE-2019-14752
>= 7.10.0 and < 7.10.20
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
6.1MEDIUM
CVE-2019-16922
>= 7.10.0 and < 7.10.20
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
5.3MEDIUM
CVE-2019-12601
>= 7.8.0 and <= 7.8.5
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
9.8CRITICAL
CVE-2019-12600
>= 7.8.0 and <= 7.8.5
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
9.8CRITICAL
CVE-2019-12599
>= 7.10.0 and < 7.10.17
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
9.8CRITICAL
CVE-2019-12598
>= 7.8.0 and <= 7.8.5
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
9.8CRITICAL
CVE-2018-20816
>= 7.0.0 and < 7.8.24
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to c
6.1MEDIUM
CVE-2019-6506
all versions
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
9.8CRITICAL
CVE-2018-15606
>= 7.0.0 and < 7.8.21
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error mess
6.1MEDIUM
CVE-2015-5948
<= 7.2.2
Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists becaus
8.1HIGH
CVE-2015-5947
<= 7.2.2
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin