Vulnerabilities > Salesagility > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-10 | CVE-2024-36408 | SQL Injection vulnerability in Salesagility Suitecrm SuiteCRM is an open-source Customer Relationship Management (CRM) software application. | 8.8 |
2024-02-20 | CVE-2024-1644 | Unspecified vulnerability in Salesagility Suitecrm 7.14.2 Suite CRM version 7.14.2 allows including local php files. | 8.8 |
2023-11-14 | CVE-2023-6130 | Unspecified vulnerability in Salesagility Suitecrm Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | 8.8 |
2023-11-14 | CVE-2023-6131 | Unspecified vulnerability in Salesagility Suitecrm Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | 8.8 |
2023-11-14 | CVE-2023-6125 | Unspecified vulnerability in Salesagility Suitecrm Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | 8.8 |
2023-07-11 | CVE-2023-3627 | Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | 8.8 |
2023-02-25 | CVE-2023-1034 | Unspecified vulnerability in Salesagility Suitecrm Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9. | 8.8 |
2022-04-15 | CVE-2022-27474 | Unspecified vulnerability in Salesagility Suitecrm 7.11.23 SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. | 7.2 |
2022-03-10 | CVE-2022-23940 | Deserialization of Untrusted Data vulnerability in Salesagility Suitecrm SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. | 8.8 |
2022-01-28 | CVE-2021-45897 | Unspecified vulnerability in Salesagility Suitecrm SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. | 8.8 |