Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-41384
Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying…
Suitecrm
Mitigation only
MEDIUM 5.3
CVE-2025-54786
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au…
Suitecrm
Mitigation only
HIGH 8.8
CVE-2025-54785
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplie…
Suitecrm
Mitigation only
HIGH 8.8
CVE-2022-45185
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to…
Suitecrm
No fix yet
HIGH 8.1
CVE-2022-45186
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
Suitecrm
No fix yet
HIGH 8.8
CVE-2024-1644
Suite CRM version 7.14.2 allows including local php files. This is possible
because the application is vulnerable to LFI.
Suitecrm
No fix yet
MEDIUM 5.0
CVE-2023-6388
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through
the vulnerable server. This is possible because the application is vulnerable…
Suitecrm
No fix yet
HIGH 7.2
CVE-2022-27474EPSS 23%
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
Suitecrm
No fix yet
CRITICAL 9.8
CVE-2019-6506
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
Suitecrm
Mitigation only