CVE-2025-54785: Salesagility Suitecrm

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.

Affected products

  • Salesagility Suitecrm: version 7.14.6 only; version 8.8.0 only

Published 2025-08-07. Last modified 2026-06-17.