Suitecrm-core
This hub aggregates every CVE we track for Suitecrm-core, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
2
0
0
0
3
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 8 most recently published vulnerabilities affecting Suitecrm-core.
- CVE-2026-32697SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user to read any record (IDOR)6.5
- CVE-2026-29109SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Processing7.2
- CVE-2026-29108Authenticated SuiteCRM Users Can Retrieve The Password Hash of Any User6.5
- CVE-2025-64493SuiteCRM is Vulnerable to Authenticated Blind SQL Injection via GraphQL6.5
- CVE-2025-64492SuiteCRM is Vulnerable to Authenticated Time Based Blind SQL Injection8.8
- CVE-2025-54786SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data5.3
- CVE-2024-36419SuiteCRM-Core Host Header Injection in /legacy 4.3
- CVE-2023-47643SuiteCRM has Unauthenticated Graphql Introspection Enabled3.1
Product normalization is registry-driven with AI assist and human review. How it works