8.8

CVSS3.1

CVE-2026-32756 - Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Module

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an authentโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:08 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.1

CVSS3.1

CVE-2026-29189 - SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship Endpoints

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and manipulate data they sโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:05 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

5

CVSS3.1

CVE-2026-29107 - SuiteCRM vulnerable to authenticated SSRF via PDF export

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `<img>` tags. When a PDF is exported using this template, the content (for example, `<img src=http://{burp_collabโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:04 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

5.9

CVSS3.1

CVE-2026-29106 - SuiteCRM has blind XSS in return_id parameter

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is encapsulated in double quotatโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:02 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

6.5

CVSS3.1

CVE-2026-32818 - Admidio is Missing Authorization on Forum Topic and Post Deletion

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does not verify whether the current user has permission to delete forum topics or posts. Both the topic_delete and post_delete actions in forum.php only validate the CSRF token but perfoโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

5.4

CVSS3.1

CVE-2026-29105 - SuiteCRM has Unauthenticated Open Redirect in Leads WebToLead Capture

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter is used as a redirectโ€ฆ

๐Ÿ“… Published: March 19, 2026, 10:58 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

5.7

CVSS3.1

CVE-2026-32816 - Admidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an anti-CSRF token. The client-side UI passes a CSRF โ€ฆ

๐Ÿ“… Published: March 19, 2026, 10:57 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

2.7

CVSS3.1

CVE-2026-29104 - SuiteCRM Vulnerable to Authenticated Arbitrary File Upload via Configurator addfontresult View in Sโ€ฆ

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an authenticated arbitrary file upload vulnerability in the Configurator module. An authenticated administrator can bypass intended file tyโ€ฆ

๐Ÿ“… Published: March 19, 2026, 10:55 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

9.1

CVSS3.1

CVE-2026-29103 - SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a dirโ€ฆ

๐Ÿ“… Published: March 19, 2026, 10:54 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.

7.2

CVSS3.1

CVE-2026-29102 - SuiteCRM has Authenticated RCE in Modules

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

๐Ÿ“… Published: March 19, 2026, 10:53 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 11:54 a.m.
Total resulsts: 340058
Page 125 of 34,006
ยซ previous page ยป next page
Filters