SugarCRM operates a customer-relationship-management platform with a modestly sized but prominent product line spanning its core CRM suite and sales applications, serving organizations across enterprise and mid-market segments. Vulnerabilities affecting the vendor skew toward a meaningful share of serious outcomes and frequently acquire public exploit code, reflecting the appeal of web-facing business applications as targets for credential theft and data access. The exposure recurs through application-layer weakness classes including code injection, SQL injection, cross-site scripting, and improper input validation, characteristic of web-application parsing and database-query construction in platforms handling sensitive customer and transaction data. Defenders should prioritize SugarCRM updates and restrict network exposure of administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sugarcrm over time
Signals from CVEs in this vendor scope (70 CVEs).
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22952HIGH In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. | Jan 11, 2023 | 8.8 | 97 | YES | YES |
CVE-2012-0694CRITICAL SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. | Oct 29, 2019 | 9.8 | 83 | NO | YES |
CVE-2019-14974MEDIUM SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. | Aug 14, 2019 | 6.1 | 59 | NO | YES |
CVE-2025-25034CRITICAL A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the Su | Jun 20, 2025 | 9.3 | 51 | NO | YES |
CVE-2018-5715MEDIUM phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). | Jan 16, 2018 | 6.1 | 43 | NO | YES |
CVE-2024-58258HIGH SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur. | Jul 13, 2025 | 7.2 | 37 | NO | YES |
CVE-2004-1227HIGH Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot | Jan 10, 2005 | 10.0 | 36 | NO | YES |
CVE-2004-1225HIGH SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a Detail | Jan 10, 2005 | 10.0 | 35 | NO | YES |
CVE-2009-2146MEDIUM Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to | Jun 22, 2009 | 6.0 | 34 | NO | YES |
CVE-2018-17784MEDIUM Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS | Oct 10, 2018 | 6.1 | 33 | NO | YES |
Signals from CVEs in this vendor scope (70 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sugarcrm.
Media articles that mention a CVE ID that affects a product developed by Sugarcrm — matched by CVE ID, not by vendor name.