Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Salesagility

First CVE: Sep 6, 2017Active for: 9 yearsTotal CVEs: 105
54.2
VTI Score
TOP TARGET

Salesagility's vulnerability footprint centers on SuiteCRM, a widely deployed open-source customer relationship management platform embedded across many organizations, yet the vendor appears in a relatively narrow product scope relative to its prominence in the landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the web-application complexity and integration depth characteristic of enterprise CRM systems. The recurring exposure concentrates in input-handling and data-processing weakness classes including SQL injection, cross-site scripting, unsafe file uploads, and deserialization of untrusted data—all endemic to large, user-facing PHP applications that process and persist customer data. Defenders should treat SuiteCRM updates as high-priority given the vendor's footprint in business-critical workflows and the sensitive nature of the data such systems handle; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
105
Total CVEs
More Total CVEs than 99% of tracked vendors
10.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Salesagility over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2017
8 years ago
Most Recent CVE
Apr 5, 2026
110 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (105 CVEs).

105 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-28328HIGH
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file
Nov 6, 20208.879NOYES
CVE-2021-42840HIGH
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can
Oct 22, 20218.878NOYES
CVE-2022-23940HIGH
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deser
Mar 10, 20228.856NONO
CVE-2024-36412CRITICAL
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows fo
Jun 10, 20249.843NOYES
CVE-2023-1034HIGH
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
Feb 25, 20238.840NONO
CVE-2023-5350CRITICAL
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
Oct 3, 20239.135NOYES
CVE-2022-27474HIGH
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
Apr 15, 20227.235NONO
CVE-2022-50589CRITICAL
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allo
Nov 6, 20259.833NONO
CVE-2021-45898CRITICAL
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
Jan 28, 20229.831NONO
CVE-2025-64492HIGH
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerab
Nov 8, 20258.830NONO
View all 105 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products105 CVEs
38%
41%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network104 (99.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low102 (97.1%)
High3 (2.9%)
Unknown0 (0.0%)
User Interaction
None78 (74.3%)
Unknown0 (0.0%)
Required27 (25.7%)
Privileges Required
Low52 (49.5%)
High4 (3.8%)
None49 (46.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (105 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
2.9% of CVEs· 98th percentile
Nuclei
2 CVEs
1.9% of CVEs· 95th percentile
ExploitDB
2 CVEs
1.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Salesagility.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Salesagility — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Salesagility's Products

View all 7 CNAs →

Top CWEs