VendorsSalesAgilitysuitecrmany version
Vulnerabilities

SalesAgility SuiteCRM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2018-20816
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
Published 2019-04-05 · Modified
6.1EPSS 0.006
CVE-2024-36419
SuiteCRM-Core Host Header Injection in /legacy
Published 2024-06-10 · Modified
6.1EPSS 0.002
CVE-2025-54783
SuiteCRM: Reflected Cross Site Scripting (XSS) through HTTP Referrer header
Published 2025-08-07 · Analyzed
6.1EPSS 0.002
CVE-2025-64491
SuiteCRM is vulnerable to unauthenticated reflected XSS through its Login page
Published 2025-11-08 · Analyzed
6.1EPSS 0.002
CVE-2021-31792
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
Published 2021-04-30 · Modified
5.4EPSS 0.009
CVE-2020-14208
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
Published 2020-11-18 · Modified
5.4EPSS 0.006
CVE-2023-6127
Unrestricted Upload of File with Dangerous Type in salesagility/suitecrm
Published 2023-11-14 · Modified
5.4EPSS 0.004
CVE-2024-50335
Authenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation in SuiteCRM
Published 2024-11-05 · Analyzed
5.4EPSS 0.003
CVE-2024-36406
SuiteCRM vulnerable to open redirects
Published 2024-06-10 · Analyzed
5.4EPSS 0.003
CVE-2021-41595
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
Published 2021-10-04 · Modified
5.3EPSS 0.018
CVE-2021-41596
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
Published 2021-10-04 · Modified
5.3EPSS 0.018
CVE-2019-16922
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
Published 2019-09-27 · Modified
5.3EPSS 0.011
CVE-2019-18782
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Published 2020-03-20 · Modified
5.3EPSS 0.009
CVE-2023-6124
Server-Side Request Forgery (SSRF) in salesagility/suitecrm
Published 2023-11-14 · Modified
5.0EPSS 0.005
CVE-2025-54787
SuiteCRM: Improper Authorization for attachment downloads
Published 2025-08-07 · Analyzed
3.7EPSS 0.002
← Prev3 / 3