Salesagility's vulnerability footprint centers on SuiteCRM, a widely deployed open-source customer relationship management platform embedded across many organizations, yet the vendor appears in a relatively narrow product scope relative to its prominence in the landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-application complexity and integration depth characteristic of enterprise CRM systems. The recurring exposure concentrates in input-handling and data-processing weakness classes including SQL injection, cross-site scripting, unsafe file uploads, and deserialization of untrusted data—all endemic to large, user-facing PHP applications that process and persist customer data. Defenders should treat SuiteCRM updates as high-priority given the vendor's footprint in business-critical workflows and the sensitive nature of the data such systems handle; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Salesagility over time
Signals from CVEs in this vendor scope (105 CVEs).
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28328HIGH SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file | Nov 6, 2020 | 8.8 | 79 | NO | YES |
CVE-2021-42840HIGH SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can | Oct 22, 2021 | 8.8 | 78 | NO | YES |
CVE-2022-23940HIGH SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deser | Mar 10, 2022 | 8.8 | 56 | NO | NO |
CVE-2024-36412CRITICAL SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows fo | Jun 10, 2024 | 9.8 | 43 | NO | YES |
CVE-2023-1034HIGH Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9. | Feb 25, 2023 | 8.8 | 40 | NO | NO |
CVE-2023-5350CRITICAL SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. | Oct 3, 2023 | 9.1 | 35 | NO | YES |
CVE-2022-27474HIGH SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. | Apr 15, 2022 | 7.2 | 35 | NO | NO |
CVE-2022-50589CRITICAL SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allo | Nov 6, 2025 | 9.8 | 33 | NO | NO |
CVE-2021-45898CRITICAL SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | Jan 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-64492HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerab | Nov 8, 2025 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (105 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Salesagility.
Media articles that mention a CVE ID that affects a product developed by Salesagility — matched by CVE ID, not by vendor name.