Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Suitecrm MEDIUM 6.1
CVE-2025-41384

Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying…

Mitigation only
Fix from $1,600 2025-10-27
Suitecrm MEDIUM 5.3
CVE-2025-54786

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au…

Mitigation only
Fix from $1,600 2025-08-07
Suitecrm HIGH 8.8
CVE-2025-54785

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplie…

Mitigation only
Fix from $1,950 2025-08-07
Suitecrm HIGH 8.8
CVE-2022-45185

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to…

No fix yet
Fix from $1,950 2025-01-07
Suitecrm HIGH 8.1
CVE-2022-45186

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

No fix yet
Fix from $1,950 2025-01-07
Suitecrm HIGH 8.8
CVE-2024-1644

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

No fix yet
Fix from $1,950 2024-02-20
Suitecrm MEDIUM 5.0
CVE-2023-6388

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable…

No fix yet
Fix from $1,600 2024-02-07
Suitecrm HIGH 7.2
CVE-2022-27474EPSS 23%

SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.

No fix yet
Fix from $1,950 2022-04-15
Suitecrm CRITICAL 9.8
CVE-2019-6506

SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.

Mitigation only
Fix from $2,300 2019-04-02