SugarCRM Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SugarCRM products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

1

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

SugarCRM KEVs Added by Year

Loading...

2 SugarCRM KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-25034

SugarCRM PHP Deserialization RCE

High Not in CISA 11 Nov 2025
CVE-2023-22952

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Confirmed In CISA 02 Feb 2023

Common Vulnerability Classes (CWE)

  • CWE-502 — Deserialization of Untrusted Data 1
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology