Cross-site scripting in SuiteCRM - CVE-2026-29100
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote attacker to inject arbitrary HTML content.
The vulnerability exists due to improper neutralization of input during web page generation in the login page when processing the default_user_name parameter. A remote attacker can supply a crafted parameter value to inject arbitrary HTML content.
User interaction is required to load the crafted login page, which may enable phishing attacks or page defacement.