PT-2026-26444 · Suitecrm · Suitecrm

Yamerooo123

·

Published

2026-03-19

·

Updated

2026-03-20

·

CVE-2026-29106

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.15.1 SuiteCRM versions prior to 8.9.3
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the return id request parameter's value is copied into an HTML tag attribute, specifically an event handler, which is enclosed in double quotation marks. This can lead to a cross-site scripting (XSS) issue.
Recommendations Update to SuiteCRM version 7.15.1 or later. Update to SuiteCRM version 8.9.3 or later. Implement a Content Security Policy (CSP) header to mitigate XSS.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-29106
GHSA-7QRJ-5HJ6-7C2M

Affected Products

Suitecrm