SugarCRM Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for SugarCRM products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
1
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
SugarCRM KEVs Added by Year
Loading...
2 SugarCRM KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-25034
SugarCRM PHP Deserialization RCE |
SugarCRM | High | Not in CISA | 11 Nov 2025 |
|
CVE-2023-22952
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. |
SugarCRM | Confirmed | In CISA | 02 Feb 2023 |
Common Vulnerability Classes (CWE)
- CWE-502 — Deserialization of Untrusted Data 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology