Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sugarcrm MEDIUM 5.4
CVE-2020-36501

Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HT…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm MEDIUM 5.4
CVE-2020-28955

SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attack…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm MEDIUM 5.4
CVE-2020-28956

Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML…

No fix yet
Fix from $1,600 2021-10-22
Sugarcrm MEDIUM 6.1
CVE-2019-14974EPSS 28%

SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

No fix yet
Fix from $1,600 2019-08-14
Sugarcrm CRITICAL 9.8
CVE-2018-6308

Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Cam…

No fix yet
Fix from $2,300 2018-01-25
Sugarcrm MEDIUM 6.1
CVE-2018-5715EPSS 7%

phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

No fix yet
Fix from $1,600 2018-01-16
Sugarcrm HIGH 7.8
CVE-2015-5946

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executab…

No fix yet
Fix from $1,950 2017-08-07
Sugarcrm HIGH 7.5
CVE-2011-4833

Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0b…

No fix yet
Fix from $1,950 2011-12-15
Sugarcrm MEDIUM 5.0
CVE-2011-3803

SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…

Mitigation only
Fix from $1,600 2011-09-24
Sugarcrm MEDIUM 6.4
CVE-2006-2460EPSS 10%

Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SES…

No fix yet
Fix from $1,600 2006-05-19
Sugar Suite HIGH 7.5
CVE-2005-4087

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlie…

No fix yet
Fix from $1,950 2005-12-08
Sugar Suite MEDIUM 5.0
CVE-2005-4086EPSS 7%

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier al…

No fix yet
Fix from $1,600 2005-12-08
Sugarcrm HIGH 10.0
CVE-2004-1225

SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via t…

No fix yet
Fix from $1,950 2005-01-10