XSS Vulnerability in SuiteCRM Email Viewer Affects Multiple Versions
CVE-2025-54784
What is CVE-2025-54784?
SuiteCRM contains a Cross Site Scripting (XSS) vulnerability in the email viewer feature, affecting versions 7.14.0 to 7.14.6. This vulnerability allows attackers to send specially crafted messages to users' inboxes. When a logged-in user views these emails, the malicious payload can execute, potentially enabling attackers to perform unauthorized actions as the user. This includes extracting sensitive data or, if the user is an administrator, completely compromising the SuiteCRM instance. Users are advised to upgrade to version 7.14.7 or later, where this vulnerability has been addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM >= 7.14.0, < 7.14.7
References
CVSS V4
Timeline
Vulnerability published
