Vulnerability index

Browse CVEs

100 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Suitecrm MEDIUM 5.4
CVE-2024-36413

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the im…

Fix: 7.14.4 / 8.6.1+
Fix from $1,600 2024-06-10
Suitecrm CRITICAL 9.8
CVE-2024-36412EPSS 6%

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events…

Fix: 7.14.4 / 8.6.1+
Fix from $2,300 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-36411

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-36409

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-36410

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-36408

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Suitecrm MEDIUM 6.5
CVE-2024-36407

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be…

Fix: 7.14.4 / 8.6.1+
Fix from $1,600 2024-06-10
Suitecrm MEDIUM 5.4
CVE-2024-36406

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows…

Fix: 7.14.4 / 8.6.1+
Fix from $1,600 2024-06-10
Suitecrm HIGH 8.8
CVE-2024-1644

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

No fix yet
Fix from $1,950 2024-02-20
Suitecrm MEDIUM 5.0
CVE-2023-6388

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable…

No fix yet
Fix from $1,600 2024-02-07
Suitecrm MEDIUM 5.3
CVE-2023-47643

SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentic…

Patch available
Fix from $1,600 2023-11-21
Suitecrm HIGH 8.8
CVE-2023-6130

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,950 2023-11-14
Suitecrm HIGH 8.8
CVE-2023-6131

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,950 2023-11-14
Suitecrm MEDIUM 5.4
CVE-2023-6127

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,600 2023-11-14
Suitecrm MEDIUM 5.4
CVE-2023-6128

Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,600 2023-11-14
Suitecrm CRITICAL 9.8
CVE-2023-6126

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $2,300 2023-11-14
Suitecrm HIGH 8.8
CVE-2023-6125

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,950 2023-11-14
Suitecrm MEDIUM 6.5
CVE-2023-5353

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

Fix: 7.14.1+
Fix from $1,600 2023-10-03
Suitecrm CRITICAL 9.1
CVE-2023-5350

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

Fix: 7.14.1+
Fix from $2,300 2023-10-03
Suitecrm MEDIUM 5.4
CVE-2023-5351

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

Fix: 7.14.1+
Fix from $1,600 2023-10-03
Suitecrm HIGH 8.8
CVE-2023-3627

Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.

Fix: 8.3.1+
Fix from $1,950 2023-07-11
Suitecrm HIGH 8.8
CVE-2023-1034EPSS 28%

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

Fix: 7.12.9+
Fix from $1,950 2023-02-25
Suitecrm HIGH 7.2
CVE-2022-27474EPSS 23%

SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.

No fix yet
Fix from $1,950 2022-04-15
Suitecrm HIGH 8.8
CVE-2022-23940EPSS 53%

SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achie…

Fix: 7.12.5 / 8.0.4+
Fix from $1,950 2022-03-10
Suitecrm MEDIUM 6.5
CVE-2022-0756

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

Fix: 7.12.5+
Fix from $1,600 2022-03-07
Suitecrm MEDIUM 6.5
CVE-2022-0754

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.

Fix: 7.12.5+
Fix from $1,600 2022-03-07
Suitecrm CRITICAL 9.8
CVE-2021-45898

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.

Fix: 7.12.3 / 8.0.2+
Fix from $2,300 2022-01-28
Suitecrm CRITICAL 9.8
CVE-2021-45899

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.

Fix: 7.12.3 / 8.0.2+
Fix from $2,300 2022-01-28
Suitecrm HIGH 8.8
CVE-2021-45897

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

Fix: 7.12.3 / 8.0.2+
Fix from $1,950 2022-01-28
Suitecrm HIGH 8.8
CVE-2021-41597

SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included …

Fix: 7.10.35 / 7.12.2+
Fix from $1,950 2022-01-12