Known vulnerabilities in SuiteCRM

Software: SuiteCRM
Software CPE: cpe:2.3:a:salesility:suitecrm:*:*:*:*:*:*:*:*
Total vulnerabilities: 91
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SuiteCRM SuiteCRM is affected by 91 known vulnerabilities: 14 high, 48 medium, 29 low Critical High Medium Low

Vulnerabilities (91)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144297 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2026-71550
CWE-98 Medium
No
No
7.15.2, 8.10.2 19.08.2026 SB2026080113
#VU144296 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-71548
CWE-89 Medium
No
No
7.15.2, 8.10.2 19.08.2026 SB2026080113
#VU141078 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-69134
CWE-89 Medium
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141077 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-69135
CWE-89 Low
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141076 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-69136
CWE-89 Low
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141075 - Server-Side Request Forgery (SSRF)
CVE-2026-69137
CWE-918 Low
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141074 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-69142
CWE-89 Medium
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141070 - Authorization Bypass Through User-Controlled Key
CVE-2026-69144
CWE-639 Low
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU141069 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-69145
CWE-89 Low
No
No
7.15.2, 8.10.2 06.08.2026 SB2026080113
#VU140694 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-63213
CWE-22 Low
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140693 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-63214
CWE-89 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140692 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-63215
CWE-89 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140691 - Server-Side Request Forgery (SSRF)
CVE-2026-63111
CWE-918 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140690 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-61648
CWE-89 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140689 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-61653
CWE-89 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140688 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-61651
CWE-89 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140687 - Server-Side Request Forgery (SSRF)
CVE-2026-61649
CWE-918 Low
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140686 - Missing Authorization
CVE-2026-61650
CWE-862 Medium
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140685 - Authorization Bypass Through User-Controlled Key
CVE-2026-63217
CWE-639 Low
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113
#VU140684 - Incorrect Authorization
CVE-2026-63218
CWE-863 Low
No
No
7.15.2, 8.10.2 01.08.2026 SB2026080113


Showing elements 1 - 20 out of 91