CVE-2023-6128: Salesagility Suitecrm

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Affected products

  • Salesagility Suitecrm: before 7.12.14 (fixed in 7.12.14); version 7.14.0 only; version 7.14.1 only; version 8.4.0 only; version 8.4.1 only

Published 2023-11-14. Last modified 2026-06-17.