VendorsSalesAgilitysuitecrmany version
Vulnerabilities

SalesAgility SuiteCRM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2024-36418
SuiteCRM authenticated RCE using connectors
Published 2024-06-10 · Modified
8.8EPSS 0.008
CVE-2024-50332
Authenticated Blind SQL Injection in DeleteRelationShip in SuiteCRM
Published 2024-11-05 · Analyzed
8.8EPSS 0.004
CVE-2024-49772
Authenticated SQL injection in AM_ProjectTemplates controller in SuiteCRM
Published 2024-11-05 · Analyzed
8.8EPSS 0.004
CVE-2025-64488
SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module
Published 2025-11-07 · Analyzed
8.8EPSS 0.004
CVE-2025-54788
SuiteCRM: Authenticated Blind SQL Injection in InboundEmail module
Published 2025-08-06 · Analyzed
8.8EPSS 0.004
CVE-2024-50333
RCE in ModuleBuilder in SuiteCRM
Published 2024-11-05 · Analyzed
8.8EPSS 0.004
CVE-2022-50590
SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality
Published 2025-11-06 · Analyzed
8.8EPSS 0.004
CVE-2023-3627
Cross-Site Request Forgery (CSRF) in salesagility/suitecrm-core
Published 2023-07-11 · Modified
8.8EPSS 0.004
CVE-2025-64492
SuiteCRM is Vulnerable to Authenticated Time Based Blind SQL Injection
Published 2025-11-08 · Analyzed
8.8EPSS 0.003
CVE-2025-64489
SuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User Bypass
Published 2025-11-08 · Analyzed
8.8EPSS 0.003
CVE-2024-36416
SuiteCRM v4 API Excessive log data DOS
Published 2024-06-10 · Modified
8.6EPSS 0.020
CVE-2025-54784
SuiteCRM is vulnerable to Cross Site Scripting (XSS) through its email viewer
Published 2025-08-07 · Analyzed
8.6EPSS 0.002
CVE-2025-64490
SuiteCRM's Inconsistent RBAC Enforcement Enables Access Control Bypass
Published 2025-11-08 · Analyzed
8.3EPSS 0.003
CVE-2015-5947
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
Published 2017-09-06 · Modified
8.1EPSS 0.027
CVE-2023-5353
Improper Access Control in salesagility/suitecrm
Published 2023-10-03 · Modified
8.1EPSS 0.006
CVE-2021-25960
SuiteCRM - CSV Injection in Accounts Module
Published 2021-09-29 · Modified
8.0EPSS 0.012
CVE-2021-25961
SuiteCRM - Account Takeover in Password Reset Functionality
Published 2021-09-29 · Modified
8.0EPSS 0.010
CVE-2020-15301
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
Published 2020-11-18 · Modified
7.8EPSS 0.008
CVE-2024-36414
SuiteCRM authenticated Server-Side Request Forgery
Published 2024-06-10 · Modified
7.7EPSS 0.004
CVE-2024-45392
SuiteCRM has wrong deletion permission checks on API delete call
Published 2024-09-05 · Analyzed
7.7EPSS 0.003
CVE-2023-3293
Cross-site Scripting (XSS) - Stored in salesagility/suitecrm-core
Published 2023-06-16 · Modified
7.6EPSS 0.005
CVE-2020-8787
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.
Published 2020-03-16 · Modified
7.5EPSS 0.009
CVE-2020-8801
SuiteCRM through 7.11.11 allows PHAR Deserialization.
Published 2020-02-13 · Modified
7.2EPSS 0.028
CVE-2024-49774
ModuleScanner flaws in SuiteCRM
Published 2024-11-05 · Analyzed
7.2EPSS 0.005
CVE-2022-0754
SQL Injection in salesagility/suitecrm
Published 2022-03-07 · Modified
7.1EPSS 0.008
CVE-2022-0755
Missing Authorization in salesagility/suitecrm
Published 2022-03-07 · Modified
7.1EPSS 0.007
CVE-2019-25664
SuiteCRM 7.10.7 SQL Injection via record Parameter
Published 2026-04-05 · Analyzed
7.1EPSS 0.003
CVE-2019-25663
SuiteCRM 7.10.7 SQL Injection via parentTab Parameter
Published 2026-04-05 · Analyzed
7.1EPSS 0.003
CVE-2023-6128
Cross-site Scripting (XSS) - Reflected in salesagility/suitecrm
Published 2023-11-14 · Modified
6.8EPSS 0.006
CVE-2020-8804
SuiteCRM through 7.11.10 allows SQL Injection via the SOAP API, the EmailUIAjax interface, or the MailMerge module.
Published 2020-02-13 · Modified
6.5EPSS 0.014
CVE-2022-0756
Missing Authorization in salesagility/suitecrm
Published 2022-03-07 · Modified
6.5EPSS 0.006
CVE-2025-64493
SuiteCRM is Vulnerable to Authenticated Blind SQL Injection via GraphQL
Published 2025-11-08 · Analyzed
6.5EPSS 0.003
CVE-2024-36407
SuiteCRM unauthenticated user password reset on php7
Published 2024-06-10 · Modified
6.5EPSS 0.003
CVE-2024-49773
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SuiteCRM
Published 2024-11-05 · Analyzed
6.5EPSS 0.003
CVE-2021-39267
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.
Published 2021-08-18 · Modified
6.1EPSS 0.020
CVE-2021-39268
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.
Published 2021-08-18 · Modified
6.1EPSS 0.014
CVE-2021-45903
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
Published 2021-12-28 · Modified
6.1EPSS 0.011
CVE-2020-15300
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
Published 2020-11-18 · Modified
6.1EPSS 0.007
CVE-2019-14752
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
Published 2019-09-30 · Modified
6.1EPSS 0.006
CVE-2018-15606
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
Published 2018-09-26 · Modified
6.1EPSS 0.006
← Prev2 / 3Next →