SuiteCRM is an open-source customer relationship management platform widely deployed in business operations, where vulnerabilities consistently center on server-side input handling and access control. The exposure recurs across SQL injection, cross-site scripting, code injection, authorization bypass, and path-traversal weaknesses that are characteristic of web-facing CRM applications, with a moderate tendency toward serious severity outcomes. Defenders should prioritize patching this platform in internet-accessible deployments and validate that administrative and user-access boundaries are properly enforced; live exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Suitecrm over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50589CRITICAL SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allo | Nov 6, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-33289CRITICAL SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists | Mar 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-33288HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists i | Mar 20, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-29099HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `retrieve()` function in `include/ | Mar 19, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-29102HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution | Mar 19, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-29189HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing A | Mar 20, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-29103HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7. | Mar 19, 2026 | 7.2 | 26 | NO | NO |
CVE-2026-29101HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerabilit | Mar 19, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-29097HIGH SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior to 7.15.1 and 8.9.3 contain a Server-Side Request Forgery ( | Mar 19, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-29096MEDIUM SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, when creating or editing a report (AOR | Mar 19, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Suitecrm.
Media articles that mention a CVE ID that affects a product developed by Suitecrm — matched by CVE ID, not by vendor name.