5.9

CVSS3.1

CVE-2026-29106 - SuiteCRM has blind XSS in return_id parameter

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is encapsulated in double quotat…

πŸ“… Published: March 19, 2026, 11:02 p.m. πŸ”„ Last Modified: March 20, 2026, 2:59 p.m.

6.5

CVSS3.1

CVE-2026-32818 - Admidio is Missing Authorization on Forum Topic and Post Deletion

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current user has permission to delete forum topics or posts. Both the topic_delete and post_delete actions in forum.php only validate the CSRF token but perfo…

πŸ“… Published: March 19, 2026, 11 p.m. πŸ”„ Last Modified: March 20, 2026, 8:25 p.m.

5.4

CVSS3.1

CVE-2026-29105 - SuiteCRM has Unauthenticated Open Redirect in Leads WebToLead Capture

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter is used as a redirect…

πŸ“… Published: March 19, 2026, 10:58 p.m. πŸ”„ Last Modified: March 20, 2026, 4:58 p.m.

5.7

CVSS3.1

CVE-2026-32816 - Admidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an anti-CSRF token. The client-side UI passes a CSRF …

πŸ“… Published: March 19, 2026, 10:57 p.m. πŸ”„ Last Modified: March 20, 2026, 5:29 p.m.

2.7

CVSS3.1

CVE-2026-29104 - SuiteCRM Vulnerable to Authenticated Arbitrary File Upload via Configurator addfontresult View in S…

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can bypass intended file ty…

πŸ“… Published: March 19, 2026, 10:55 p.m. πŸ”„ Last Modified: March 21, 2026, 3:09 a.m.

9.1

CVSS3.1

CVE-2026-29103 - SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a dir…

πŸ“… Published: March 19, 2026, 10:54 p.m. πŸ”„ Last Modified: March 20, 2026, 8:07 p.m.

7.2

CVSS3.1

CVE-2026-29102 - SuiteCRM has Authenticated RCE in Modules

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

πŸ“… Published: March 19, 2026, 10:53 p.m. πŸ”„ Last Modified: March 20, 2026, 3 p.m.

5.7

CVSS3.1

CVE-2026-32755 - Admidio is Missing CSRF Protection on Role Membership Date Changes

Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. The handler checks stop_membership and remove_for…

πŸ“… Published: March 19, 2026, 10:53 p.m. πŸ”„ Last Modified: March 19, 2026, 10:53 p.m.

4.9

CVSS3.1

CVE-2026-29101 - SuiteCRM Vulnerable to Directory Traversal to DoS in Modules

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

πŸ“… Published: March 19, 2026, 10:51 p.m. πŸ”„ Last Modified: March 20, 2026, 4:59 p.m.

7.1

CVSS3.1

CVE-2026-29100 - SuiteCRM has Reflected HTML Injection in Login Page via default_user_name Parameter

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML injection vulnerability in the login page that allows attackers to inject arbitrary HTML content, enabling phishing attacks and page defacement. Versio…

πŸ“… Published: March 19, 2026, 10:48 p.m. πŸ”„ Last Modified: March 21, 2026, 3:10 a.m.
Total resulsts: 339221
Page 42 of 33,923
Β« previous page Β» next page
Filters