CVE-2026-29100

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML injection vulnerability in the login page that allows attackers to inject arbitrary HTML content, enabling phishing attacks and page defacement. Version 7.15.1 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-19 23:16

Updated : 2026-03-24 14:39


NVD link : CVE-2026-29100

Mitre link : CVE-2026-29100

CVE.ORG link : CVE-2026-29100


JSON object : View

Products Affected

suitecrm

  • suitecrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')