VendorsSalesAgilitysuitecrmany version
Vulnerabilities

SalesAgility SuiteCRM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2024-36412
SuiteCRM unauthenticated SQL Injection
Published 2024-06-10 · Modified
10.0EPSS 0.057
CVE-2020-8803
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
Published 2020-02-13 · Modified
9.8EPSS 0.033
CVE-2020-8802
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
Published 2020-02-13 · Modified
9.8EPSS 0.026
CVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
Published 2022-01-28 · Modified
9.8EPSS 0.022
CVE-2019-14454
SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
Published 2019-10-02 · Modified
9.8EPSS 0.015
CVE-2019-13335
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
Published 2019-10-02 · Modified
9.8EPSS 0.013
CVE-2020-8784
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).
Published 2020-03-16 · Modified
9.8EPSS 0.011
CVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
Published 2022-01-28 · Modified
9.8EPSS 0.011
CVE-2019-12598
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).
Published 2019-06-07 · Modified
9.8EPSS 0.011
CVE-2019-12599
SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.
Published 2019-06-07 · Modified
9.8EPSS 0.011
CVE-2019-12601
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).
Published 2019-06-07 · Modified
9.8EPSS 0.011
CVE-2019-12600
SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).
Published 2019-06-07 · Modified
9.8EPSS 0.011
CVE-2020-8786
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).
Published 2020-03-16 · Modified
9.8EPSS 0.011
CVE-2020-8783
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).
Published 2020-03-16 · Modified
9.8EPSS 0.011
CVE-2020-8785
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).
Published 2020-03-16 · Modified
9.8EPSS 0.011
CVE-2019-18784
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
Published 2019-11-06 · Modified
9.8EPSS 0.011
CVE-2023-6126
Code Injection in salesagility/suitecrm
Published 2023-11-14 · Modified
9.8EPSS 0.007
CVE-2022-50589
SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality
Published 2025-11-06 · Analyzed
9.8EPSS 0.006
CVE-2024-36408
SuiteCRM authenticated SQL Injection in Alerts
Published 2024-06-10 · Modified
9.6EPSS 0.005
CVE-2024-36409
SuiteCRM authenticated SQL Injection in TreeData entrypoint
Published 2024-06-10 · Modified
9.6EPSS 0.004
CVE-2024-36411
SuiteCRM authenticated SQL Injection in EmailUIAjax displayView controller
Published 2024-06-10 · Modified
9.6EPSS 0.004
CVE-2024-36410
SuiteCRM authenticated SQL Injection in EmailUIAjax messages count controller
Published 2024-06-10 · Modified
9.6EPSS 0.004
CVE-2015-5948
Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947.
Published 2017-09-06 · Modified
9.3EPSS 0.045
CVE-2023-5350
SQL Injection in salesagility/suitecrm
Published 2023-10-03 · Modified
9.1EPSS 0.019
CVE-2024-36415
SuiteCRM Improper Control of Filename for Include Statement in PHP and Unrestricted Upload of File with Dangerous content leads to authenticated remote code execution
Published 2024-06-10 · Modified
9.1EPSS 0.009
CVE-2020-28328
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
Published 2020-11-06 · Modified
9.01 PoCEPSS 0.633
CVE-2021-42840
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this issue exists because of an incomplete fix for CVE-2020-28328.
Published 2021-10-22 · Modified
9.01 PoCEPSS 0.589
CVE-2024-36417
SuiteCRM Stored XSS Vulnerability Allows Code Execution via Malicious iFrame
Published 2024-06-10 · Modified
9.0EPSS 0.004
CVE-2023-5351
Cross-site Scripting (XSS) - Stored in salesagility/suitecrm
Published 2023-10-03 · Modified
8.9EPSS 0.005
CVE-2024-36413
SuiteCRM authenticated Reflected Cross-Site Scripting
Published 2024-06-10 · Modified
8.9EPSS 0.003
CVE-2022-23940
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a PHP-deserialization payload in the email_recipients field. Once someone accesses this report, the backend will deserialize the content of the email_recipients field and the payload gets executed. Project dependencies include a number of interesting PHP deserialization gadgets (e.g., Monolog/RCE1 from phpggc) that can be used for Code Execution.
Published 2022-03-07 · Modified
8.8EPSS 0.532
CVE-2023-1034
Path Traversal: '\..\filename' in salesagility/suitecrm
Published 2023-02-25 · Modified
8.8EPSS 0.281
CVE-2021-45897
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
Published 2022-01-28 · Modified
8.8EPSS 0.046
CVE-2020-8800
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
Published 2020-02-13 · Modified
8.8EPSS 0.028
CVE-2021-45041
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
Published 2021-12-19 · Modified
8.8EPSS 0.022
CVE-2021-41869
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
Published 2021-10-04 · Modified
8.8EPSS 0.016
CVE-2021-41597
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
Published 2022-01-12 · Modified
8.8EPSS 0.010
CVE-2023-6131
Code Injection in salesagility/suitecrm
Published 2023-11-14 · Modified
8.8EPSS 0.010
CVE-2023-6130
Path Traversal: '\..\filename' in salesagility/suitecrm
Published 2023-11-14 · Modified
8.8EPSS 0.010
CVE-2023-6125
Code Injection in salesagility/suitecrm
Published 2023-11-14 · Modified
8.8EPSS 0.008
1 / 3Next →