CVEs we hold for Suitecrm
Records whose assigning authority named Suitecrm as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-32697SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user to read any record…SuiteCRM-Core
CVE-2026-29189SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship EndpointsSuiteCRM
CVE-2026-29109SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter ProcessingSuiteCRM-Core
CVE-2026-29104SuiteCRM Vulnerable to Authenticated Arbitrary File Upload via Configurator addfontresult View in SuiteCRMSuiteCRM
CVE-2026-29103SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner BypassSuiteCRM
CVE-2026-29100SuiteCRM has Reflected HTML Injection in Login Page via default_user_name ParameterSuiteCRM
CVE-2026-29099SuiteCRM has Authenticated Blind SQL Injection in OutboundEmail Legacy Functionality.SuiteCRM
CVE-2026-29098SuiteCRM has Relative Path Traversal via ModuleBuilder Modules ExportCustom ActionSuiteCRM
CVE-2026-29097SuiteCRM Server-Side Request Forgery and Denial of Service via RSS Feed DashletSuiteCRM
CVE-2026-29096SuiteCRM vulnerable to Authenticated SQL Injection via unsanitized field_function in Report FieldsSuiteCRM
CVE-2025-64491SuiteCRM is vulnerable to unauthenticated reflected XSS through its Login pageSuiteCRM
CVE-2025-64489SuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User BypassSuiteCRM
CVE-2025-54786SuiteCRM: Legacy iCal service allows unauthenticated access to meeting dataSuiteCRM-Core
35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.