CVE-2026-29106Patch(suitecrm / suitecrm)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch suitecrm suitecrm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is encapsulated in double quotation marks. Versions 7.15.1 and 8.9.3 patch the issue. Users should also use a Content Security Policy (CSP) header to completely mitigate XSS.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-80CWE-116CWE-159

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
suitecrm

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-20: 103-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Patch

    CVE-2026-29106 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_… https://www.cve.org/CVERecord?id=CVE-2026-29106

    Post summary

    The text identifies a SuiteCRM vulnerability and notes that it is fixed in versions 7.15.1 and 8.9.3, but provides no further technical or exploit details.

    00000125
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsuitecrmsuitecrm---

Explore more