Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2019-17317
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Sugarcrm Sugarcrm
6.5
CVSSv2
CVE-2019-17319
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Emails module by a Regular user.
Sugarcrm Sugarcrm
4.3
CVSSv2
CVE-2019-14974
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
Sugarcrm Sugarcrm 9.0.0
1 EDB exploit
4.3
CVSSv2
CVE-2018-17784
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote malicious user to conduct a cross-site scripting (XSS) attack on a targeted system.
Sugarcrm Sugarcrm
1 EDB exploit
7.5
CVSSv2
CVE-2014-3244
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM prior to 6.5.17 allows remote malicious users to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Sugarcrm Sugarcrm
7.5
CVSSv2
CVE-2018-6308
Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name parameter to modules\Configurator\controller.php and modules\Currencies\Currency.php, t...
Sugarcrm Sugarcrm 6.5.26
4.3
CVSSv2
CVE-2018-5715
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Sugarcrm Sugarcrm 3.5.1
1 EDB exploit
6.5
CVSSv2
CVE-2017-14508
An issue exists in SugarCRM prior to 7.7.2.3, 7.8.x prior to 7.8.2.2, and 7.9.x prior to 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonst...
Sugarcrm Sugarcrm 6.5.26
Sugarcrm Sugarcrm 7.8.0.1
Sugarcrm Sugarcrm 7.8.0.0
Sugarcrm Sugarcrm 7.8.2.0
Sugarcrm Sugarcrm 7.8.1.0
Sugarcrm Sugarcrm 7.9.0.0
Sugarcrm Sugarcrm 7.8.2.1
Sugarcrm Sugarcrm 7.9.1.0
Sugarcrm Sugarcrm 7.9.0.1
Sugarcrm Sugarcrm
6.5
CVSSv2
CVE-2017-14509
An issue exists in SugarCRM prior to 7.7.2.3, 7.8.x prior to 7.8.2.2, and 7.9.x prior to 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via...
Sugarcrm Sugarcrm 7.9.1.0
Sugarcrm Sugarcrm 7.9.0.1
Sugarcrm Sugarcrm
Sugarcrm Sugarcrm 6.5.26
Sugarcrm Sugarcrm 7.8.0.1
Sugarcrm Sugarcrm 7.8.0.0
Sugarcrm Sugarcrm 7.8.2.0
Sugarcrm Sugarcrm 7.8.1.0
Sugarcrm Sugarcrm 7.9.0.0
Sugarcrm Sugarcrm 7.8.2.1
4.3
CVSSv2
CVE-2017-14510
An issue exists in SugarCRM prior to 7.7.2.3, 7.8.x prior to 7.8.2.2, and 7.9.x prior to 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by ...
Sugarcrm Sugarcrm 7.9.1.0
Sugarcrm Sugarcrm 7.9.0.1
Sugarcrm Sugarcrm
Sugarcrm Sugarcrm 6.5.26
Sugarcrm Sugarcrm 7.8.0.1
Sugarcrm Sugarcrm 7.8.0.0
Sugarcrm Sugarcrm 7.8.2.0
Sugarcrm Sugarcrm 7.8.1.0
Sugarcrm Sugarcrm 7.9.0.0
Sugarcrm Sugarcrm 7.8.2.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »