Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sugarcrm HIGH 8.8
CVE-2023-46815

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes…

Fix: 12.0.4+
Fix from $1,950 2023-10-27
Sugarcrm HIGH 8.8
CVE-2023-46816

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified …

Fix: 12.0.4+
Fix from $1,950 2023-10-27
Sugarcrm HIGH 8.8
CVE-2023-35808

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Sugarcrm HIGH 8.8
CVE-2023-35809

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Sugarcrm HIGH 8.8
CVE-2023-35811

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. …

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Sugarcrm HIGH 7.2
CVE-2023-35810

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Sugarcrm HIGH 8.8
CVE-2023-22952 KEVEPSS 80%

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Fix: 11.0.5 / 12.0.2+
Fix from $1,950 2023-01-11
Sugarcrm MEDIUM 5.4
CVE-2020-36501

Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HT…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm MEDIUM 5.4
CVE-2020-28955

SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attack…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm MEDIUM 5.4
CVE-2020-28956

Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm CRITICAL 9.8
CVE-2020-7472

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…

Fix: 8.0.7 / 9.0.4+
Fix from $2,300 2020-11-12
Sugarcrm MEDIUM 5.4
CVE-2020-17372

SugarCRM before 10.1.0 (Q3 2020) allows XSS.

Fix: 10.1.0+
Fix from $1,600 2020-08-12
Sugarcrm MEDIUM 5.3
CVE-2020-17373

SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.

Fix: 10.1.0+
Fix from $1,600 2020-08-12
Sugarcrm CRITICAL 9.8
CVE-2012-0694EPSS 67%

SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.

Fix: after 6.3.1
Fix from $2,300 2019-10-29
Sugarcrm HIGH 8.8
CVE-2019-17311

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17312

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17313

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17314

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17297

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17298

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17300

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17302

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17303

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17305

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17308

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17299

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17301

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17304

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17306

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17307

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07