CVE-2026-29106 MEDIUM

CVE-2026-29106: SuiteCRM has blind XSS in return_id parameter

Vendor Suitecrm
Product SuiteCRM
Weakness CWE-79 · XSS
Published March 19, 2026
Last update March 20, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request parameter is copied into the value of an HTML tag attribute which is an event handler and is encapsulated in double quotation marks. Versions 7.15.1 and 8.9.3 patch the issue. Users should also use a Content Security Policy (CSP) header to completely mitigate XSS.

Key dates

02Disclosure timeline

March 19, 2026 CVE published
March 20, 2026 Record updated