PT-2026-26438 · Suitecrm · Suitecrm

Dimitrop

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-29100

CVSS v3.1

7.1

High

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML injection vulnerability in the login page that allows attackers to inject arbitrary HTML content, enabling phishing attacks and page defacement. Version 7.15.1 patches the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-29100

Affected Products

Suitecrm