Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm sugarcrm vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2019-17318
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
Sugarcrm Sugarcrm
668
VMScore
CVE-2020-7472
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM prior to 8.0, 8.0 prior to 8.0.7, 9.0 prior to 9.0.4, and 10.0 prior to 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via cr...
Sugarcrm Sugarcrm
605
VMScore
CVE-2006-6712
Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in crafted email messages.
Sugarcrm Sugarcrm
312
VMScore
CVE-2020-17373
SugarCRM prior to 10.1.0 (Q3 2020) allows SQL Injection.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17295
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the history function by a Regular user.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17296
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Contacts module by a Regular user.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17298
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Administration module by a Developer user.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17306
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17307
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
Sugarcrm Sugarcrm
578
VMScore
CVE-2019-17308
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Emails module by a Regular user.
Sugarcrm Sugarcrm
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »