HarborGuard / CVE
Back to search
HIGHCVE-2026-29100Published Modified CNA GitHub_M

CVE-2026-29100: SuiteCRM has Reflected HTML Injection in Login Page via default_user_name Parameter

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15.0 contains a reflected HTML injection vulnerability in the login page that allows attackers to inject arbitrary HTML content, enabling phishing attacks and page defacement. Version 7.15.1 patches the issue.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • SuiteCRM / SuiteCRM
    < 7.15.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CVE-2026-29100: SuiteCRM has Reflected HTML Injection in Login Page via default_user_name Parameter | HarborGuard CVE