VendorsSalesAgilitysuitecrmall versions
Vulnerabilities

SalesAgility SuiteCRM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2021-39267
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.
Published 2021-08-18 · Modified
6.1EPSS 0.020
CVE-2021-39268
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.
Published 2021-08-18 · Modified
6.1EPSS 0.014
CVE-2021-45903
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
Published 2021-12-28 · Modified
6.1EPSS 0.011
CVE-2020-15300
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
Published 2020-11-18 · Modified
6.1EPSS 0.007
CVE-2019-14752
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
Published 2019-09-30 · Modified
6.1EPSS 0.006
CVE-2018-15606
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
Published 2018-09-26 · Modified
6.1EPSS 0.006
CVE-2018-20816
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
Published 2019-04-05 · Modified
6.1EPSS 0.006
CVE-2024-36419
SuiteCRM-Core Host Header Injection in /legacy
Published 2024-06-10 · Modified
6.1EPSS 0.002
CVE-2025-54783
SuiteCRM: Reflected Cross Site Scripting (XSS) through HTTP Referrer header
Published 2025-08-07 · Analyzed
6.1EPSS 0.002
CVE-2025-64491
SuiteCRM is vulnerable to unauthenticated reflected XSS through its Login page
Published 2025-11-08 · Analyzed
6.1EPSS 0.002
CVE-2025-41384
Reflected Cross-Site Scripting (XSS) in SuiteCRM
Published 2025-10-27 · Analyzed
6.1EPSS 0.002
CVE-2021-31792
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
Published 2021-04-30 · Modified
5.4EPSS 0.009
CVE-2020-14208
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
Published 2020-11-18 · Modified
5.4EPSS 0.006
CVE-2023-6127
Unrestricted Upload of File with Dangerous Type in salesagility/suitecrm
Published 2023-11-14 · Modified
5.4EPSS 0.004
CVE-2024-50335
Authenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation in SuiteCRM
Published 2024-11-05 · Analyzed
5.4EPSS 0.003
CVE-2024-36406
SuiteCRM vulnerable to open redirects
Published 2024-06-10 · Analyzed
5.4EPSS 0.003
CVE-2023-47643
SuiteCRM has Unauthenticated Graphql Introspection Enabled
Published 2023-11-21 · Modified
5.3EPSS 0.030
CVE-2021-41595
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
Published 2021-10-04 · Modified
5.3EPSS 0.018
CVE-2021-41596
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
Published 2021-10-04 · Modified
5.3EPSS 0.018
CVE-2019-16922
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
Published 2019-09-27 · Modified
5.3EPSS 0.011
CVE-2019-18782
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Published 2020-03-20 · Modified
5.3EPSS 0.009
CVE-2025-54786
SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data
Published 2025-08-06 · Analyzed
5.3EPSS 0.003
CVE-2023-6124
Server-Side Request Forgery (SSRF) in salesagility/suitecrm
Published 2023-11-14 · Modified
5.0EPSS 0.005
CVE-2023-6388
Suite CRM v7.14.2 - SSRF
Published 2024-02-07 · Modified
5.0EPSS 0.005
CVE-2025-54787
SuiteCRM: Improper Authorization for attachment downloads
Published 2025-08-07 · Analyzed
3.7EPSS 0.002
← Prev3 / 3