Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sugarcrm

First CVE: Jan 1, 2005Active for: 22 yearsTotal CVEs: 70
69.3
VTI Score
TOP TARGET

SugarCRM operates a customer-relationship-management platform with a modestly sized but prominent product line spanning its core CRM suite and sales applications, serving organizations across enterprise and mid-market segments. Vulnerabilities affecting the vendor skew toward a meaningful share of serious outcomes and frequently acquire public exploit code, reflecting the appeal of web-facing business applications as targets for credential theft and data access. The exposure recurs through application-layer weakness classes including code injection, SQL injection, cross-site scripting, and improper input validation, characteristic of web-application parsing and database-query construction in platforms handling sensitive customer and transaction data. Defenders should prioritize SugarCRM updates and restrict network exposure of administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
70
Total CVEs
More Total CVEs than 99% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
1.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sugarcrm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 2005
21 years ago
Most Recent CVE
Jul 13, 2025
376 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (70 CVEs).

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-22952HIGH
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Jan 11, 20238.897YESYES
CVE-2012-0694CRITICAL
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Oct 29, 20199.883NOYES
CVE-2019-14974MEDIUM
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
Aug 14, 20196.159NOYES
CVE-2025-25034CRITICAL
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the Su
Jun 20, 20259.351NOYES
CVE-2018-5715MEDIUM
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Jan 16, 20186.143NOYES
CVE-2024-58258HIGH
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
Jul 13, 20257.237NOYES
CVE-2004-1227HIGH
Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot
Jan 10, 200510.036NOYES
CVE-2004-1225HIGH
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a Detail
Jan 10, 200510.035NOYES
CVE-2009-2146MEDIUM
Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to
Jun 22, 20096.034NOYES
CVE-2018-17784MEDIUM
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS
Oct 10, 20186.133NOYES
View all 70 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products70 CVEs
29%
64%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.4%)
Network52 (74.3%)
Unknown17 (24.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (74.3%)
High1 (1.4%)
Unknown17 (24.3%)
User Interaction
None45 (64.3%)
Unknown17 (24.3%)
Required8 (11.4%)
Privileges Required
Low31 (44.3%)
High12 (17.1%)
None10 (14.3%)
Unknown17 (24.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (70 CVEs).

CISA KEV
1 CVE
1.4% of CVEs· 99th percentile
Metasploit
3 CVEs
4.3% of CVEs· 98th percentile
Nuclei
4 CVEs
5.7% of CVEs· 96th percentile
ExploitDB
14 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sugarcrm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sugarcrm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sugarcrm's Products

View all 2 CNAs →

Top CWEs