« Volver al listado

Salesagility

Salesagility Suitecrm: vulnerabilidades y CVE

Salesagility Suitecrm tiene 105 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 21 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE105
Últimos 12 meses11
Críticas21
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-25664Alta (7.1)0.34%—5 abr 2026
SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append…
CVE-2019-25663Alta (7.1)0.34%—5 abr 2026
SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the…
CVE-2025-64493Media (6.5)0.33%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the…
CVE-2025-64492Alta (8.8)0.34%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an…
CVE-2025-64491Media (6.1)0.20%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation…
CVE-2025-64490Alta (8.3)0.27%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view…
CVE-2025-64489Alta (8.8)0.34%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user…
CVE-2025-64488Alta (8.6)0.43%—8 nov 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious…
CVE-2022-50590Alta (8.8)0.36%—6 nov 2025
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated…
CVE-2022-50589Crítica (9.3)0.64%—6 nov 2025
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to…
CVE-2025-41384Media (5.1)0.19%—27 oct 2025
Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious…
CVE-2025-54787Baja (3.7)0.23%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the…
CVE-2025-54784Alta (8.6)0.21%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An…
CVE-2025-54783Media (5.1)0.21%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an…
CVE-2025-54788Alta (8.8)0.42%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database,…
CVE-2025-54786Media (5.3)0.29%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access…
CVE-2025-54785Alta (8.8)0.38%—7 ago 2025
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the…
CVE-2022-45186Alta (8.1)0.56%—7 ene 2025
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
CVE-2022-45185Alta (8.8)1.1%—7 ene 2025
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.
CVE-2024-50335Media (5.4)0.30%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS),…
CVE-2024-50333Alta (8.8)0.40%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function can be used…
CVE-2024-50332Alta (8.8)0.45%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been…
CVE-2024-49774Alta (7.2)0.50%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But this checks…
CVE-2024-49773Media (6.5)0.30%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled input is…
CVE-2024-49772Alta (8.8)0.45%—5 nov 2024
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection attack.…
CVE-2024-45392Media (4.3)0.28%—5 sept 2024
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and…
CVE-2024-36419Media (6.1)0.24%—10 jun 2024
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability in versions prior to 8.6.1 allows for Host Header Injection when directly accessing the `/legacy` route. Version…
CVE-2024-36418Alta (8.8)0.80%—10 jun 2024
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connectors allows an authenticated user to perform a remote code execution…
CVE-2024-36417Crítica (9)0.41%—10 jun 2024
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, an unverified IFrame can be added some some inputs, which could allow for a cross-site…
CVE-2024-36416Alta (7.5)2.0%—10 jun 2024
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows denial of service by logging excessive…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services14
  2. T1005 Data from Local System9
  3. T1059 Command and Scripting Interpreter4
  4. T1190 Exploit Public-Facing Application2
  5. T1059.007 JavaScript1
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.