CVE-2026-29107

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
19/03/2026
Last modified:
24/03/2026

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, it is possible to create PDF templates with `` tags. When a PDF is exported using this template, the content (for example, `` is rendered server side, and thus a request is issued from the server, resulting in Server-Side Request Forgery. Versions 7.15.1 and 8.9.3 patch the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* 7.15.1 (excluding)
cpe:2.3:a:suitecrm:suitecrm:*:*:*:*:*:*:*:* 8.0.0 (including) 8.9.3 (excluding)