📦 Suitecrm

by Salesagility

🔍 What is Suitecrm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-50589

CRITICAL CVSS 9.8 Nov 6, 2025

This is a critical SQL injection vulnerability in SuiteCRM's export functionality that allows unauthenticated remote attackers to execute arbitrary SQL commands. Successful exploitation can lead to re...

CVE-2024-36415

CRITICAL CVSS 9.1 Jun 10, 2024

This vulnerability in SuiteCRM allows attackers to upload malicious files that bypass verification checks, leading to remote code execution. All SuiteCRM instances prior to versions 7.14.4 and 8.6.1 a...

CVE-2024-36412

CRITICAL CVSS 10.0 Jun 10, 2024

This is a critical SQL injection vulnerability in SuiteCRM that allows attackers to execute arbitrary SQL commands through the events response entry point. All SuiteCRM instances running versions prio...

CVE-2024-36409

CRITICAL CVSS 9.6 Jun 10, 2024

This CVE describes a SQL injection vulnerability in SuiteCRM's Tree data entry point due to poor input validation. Attackers can execute arbitrary SQL commands, potentially compromising the database. ...

CVE-2024-36408

CRITICAL CVSS 9.6 Jun 10, 2024

This CVE describes a SQL injection vulnerability in SuiteCRM's Alerts controller due to poor input validation. Attackers can execute arbitrary SQL commands, potentially compromising the CRM database. ...

CVE-2024-1644

CRITICAL CVSS 9.9 Feb 20, 2024

Suite CRM version 7.14.2 contains a Local File Inclusion (LFI) vulnerability that allows attackers to include and execute arbitrary PHP files from the local filesystem. This affects all organizations ...

CVE-2023-5350

CRITICAL CVSS 9.1 Oct 3, 2023

This CVE describes a SQL injection vulnerability in SuiteCRM versions prior to 7.14.1. Attackers can inject malicious SQL queries through user-controlled inputs, potentially allowing unauthorized data...

CVE-2021-45898

CRITICAL CVSS 9.8 Jan 28, 2022

This vulnerability allows attackers to include local files on the server through SuiteCRM, potentially leading to sensitive information disclosure or remote code execution. It affects SuiteCRM install...

CVE-2025-64492

HIGH CVSS 8.8 Nov 8, 2025

SuiteCRM versions 8.9.0 and below contain a time-based blind SQL injection vulnerability that allows authenticated attackers to infer database information by measuring response time differences. This ...

CVE-2025-64489

HIGH CVSS 8.3 Nov 8, 2025

SuiteCRM versions 7.14.7 and prior, and 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions remain active after account deactivation. This allows deactivated us...

CVE-2025-64490

HIGH CVSS 8.3 Nov 8, 2025

SuiteCRM versions 7.14.7 and prior, and 8.0.0-beta.1 through 8.9.0 have an access control vulnerability where low-privileged users can view and create work items through Resource Calendar and project ...

CVE-2025-64488

HIGH CVSS 8.8 Nov 8, 2025

This SQL injection vulnerability in SuiteCRM allows attackers to manipulate SQL queries via malicious call_id parameters, potentially leading to unauthorized data access, database compromise, and data...

CVE-2025-54788

HIGH CVSS 8.8 Aug 7, 2025

This SQL injection vulnerability in SuiteCRM's InboundEmail module allows attackers to execute arbitrary database queries. All SuiteCRM instances running versions below 7.14.7 are affected, potentiall...

CVE-2025-54785

HIGH CVSS 8.8 Aug 7, 2025

SuiteCRM versions 7.14.6 and 8.8.0 contain an insecure deserialization vulnerability where user input is passed directly to PHP's unserialize() function without proper validation. This allows attacker...

CVE-2022-45185

HIGH CVSS 8.8 Jan 7, 2025

SuiteCRM 7.12.7 contains an authenticated file upload vulnerability that allows authenticated users to upload malicious files. When combined with insecure deserialization, this can lead to remote code...

CVE-2022-45186

HIGH CVSS 8.1 Jan 7, 2025

SuiteCRM 7.12.7 contains an authenticated data disclosure vulnerability that allows authenticated users to retrieve arbitrary database fields they shouldn't have access to. This affects all organizati...

CVE-2024-49774

HIGH CVSS 7.2 Nov 5, 2024

SuiteCRM versions before 7.14.6 and 8.7.1 contain a vulnerability in their malicious MLP (Module Loadable Package) prevention mechanism. Attackers can bypass the function/method blacklist using specif...

CVE-2024-49772

HIGH CVSS 8.8 Nov 5, 2024

SuiteCRM versions 7.14.4 have a SQL injection vulnerability that allows authenticated users with low privileges to execute arbitrary SQL queries. This can lead to complete database compromise, exposin...

CVE-2024-45392

HIGH CVSS 7.7 Sep 5, 2024

SuiteCRM versions before 7.14.5 and 8.6.2 have an insufficient access control vulnerability in the API that allows authenticated attackers to delete records they shouldn't have permission to delete. T...

CVE-2024-36418

HIGH CVSS 8.5 Jun 10, 2024

This vulnerability in SuiteCRM allows authenticated users to execute arbitrary code remotely through connectors. It affects all SuiteCRM installations prior to versions 7.14.4 and 8.6.1. Attackers wit...

CVE-2024-36414

HIGH CVSS 7.7 Jun 10, 2024

This vulnerability in SuiteCRM allows attackers to perform server-side request forgery (SSRF) attacks through the connectors file verification feature. It affects all SuiteCRM installations prior to v...

CVE-2023-3627

HIGH CVSS 8.8 Jul 11, 2023

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in SuiteCRM Core that allows attackers to trick authenticated users into performing unintended actions. Attackers can exploit this ...

CVE-2022-27474

HIGH CVSS 7.2 Apr 15, 2022

CVE-2022-27474 is a remote code execution vulnerability in SuiteCRM v7.11.23 that allows attackers to execute arbitrary code by injecting a crafted payload into the FirstName text field. This affects ...

CVE-2021-45897

HIGH CVSS 8.8 Jan 28, 2022

This vulnerability allows remote attackers to execute arbitrary code on SuiteCRM installations. It affects SuiteCRM versions before 7.12.3 and 8.x before 8.0.2. Attackers can exploit this without auth...

CVE-2021-42840

HIGH CVSS 8.8 Oct 22, 2021

SuiteCRM versions before 7.11.19 allow remote code execution via the Log File Name setting in system settings. Attackers who compromise admin accounts can set logger_file_name to point to malicious PH...

CVE-2021-25960

HIGH CVSS 8.0 Sep 29, 2021

This is a CSV injection vulnerability in SuiteCRM that allows low-privileged attackers to inject malicious formulas into input fields. When an administrator exports account data as a CSV file and open...

CVE-2025-64493

MEDIUM CVSS 6.5 Nov 8, 2025

SuiteCRM versions 8.6.0 through 8.9.0 contain an authenticated blind SQL injection vulnerability in the GraphQL API's appMetadata operation. This allows authenticated users (without administrative pri...

CVE-2025-64491

MEDIUM CVSS 6.1 Nov 8, 2025

SuiteCRM versions 7.14.7 and below contain an unauthenticated reflected XSS vulnerability that allows attackers to execute arbitrary JavaScript in victims' browsers. This could lead to credential thef...

CVE-2022-50590

MEDIUM CVSS 5.3 Nov 6, 2025

This vulnerability allows remote unauthenticated attackers to exploit a type confusion flaw in SuiteCRM's deleteAttachment functionality to modify database objects. Attackers could change administrato...

CVE-2025-41384

MEDIUM CVSS 6.1 Oct 27, 2025

This reflected XSS vulnerability in SuiteCRM v7.14.1 allows attackers to execute arbitrary JavaScript code by manipulating the HTTP Referer header. The vulnerability affects all users of the vulnerabl...

CVE-2025-54784

MEDIUM CVSS 6.1 Aug 7, 2025

SuiteCRM versions 7.14.0 through 7.14.6 contain a stored XSS vulnerability in the email viewer. An attacker can send a malicious email that executes JavaScript when viewed by any authenticated user, p...

CVE-2025-54783

MEDIUM CVSS 6.1 Aug 7, 2025

SuiteCRM versions 7.14.6 and below contain a reflected cross-site scripting (XSS) vulnerability that allows attackers to execute arbitrary JavaScript code by manipulating the HTTP Referer header. This...

CVE-2024-50333

MEDIUM CVSS 6.6 Nov 5, 2024

SuiteCRM has an input validation vulnerability in the ParserLabel::addLabels() function that allows attackers to write arbitrary data to custom language files. This can lead to remote code execution w...

CVE-2024-36419

MEDIUM CVSS 4.3 Jun 10, 2024

SuiteCRM versions before 8.6.1 contain a Host Header Injection vulnerability in the /legacy route. This allows attackers to manipulate host headers to potentially redirect users to malicious sites or ...

CVE-2024-36417

MEDIUM CVSS 5.7 Jun 10, 2024

SuiteCRM versions before 7.14.4 and 8.6.1 allow unverified IFrames in certain input fields, enabling cross-site scripting (XSS) attacks. This vulnerability affects all SuiteCRM users running vulnerabl...

CVE-2024-36406

MEDIUM CVSS 5.4 Jun 10, 2024

SuiteCRM versions before 7.14.4 and 8.6.1 contain an open redirect vulnerability due to unchecked input. This allows attackers to redirect users to malicious websites after they click on manipulated l...