CVE-2025-64493: Salesagility Suitecrm
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.
Affected products
- Salesagility Suitecrm: from 8.6.0, before 8.9.1 (fixed in 8.9.1)
Published 2025-11-08. Last modified 2026-06-17.