Vulnerability Database

318,275

Total vulnerabilities in the database

CVE-2024-36410

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • Published: Jun 10, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-36410
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.6
  • AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

CWEs:

OWASP TOP 10: