Released 6 November 2025
CVE: CVE-2025-64488: SQL Injection Vulnerability | GitHub Advisory | Reporter: allannjuguna
CVE: CVE-2025-64489: Privilege Escalation Vulnerability | GitHub Advisory | Reporter: prakhar0x01
CVE: CVE-2025-64490: Improper Access Control | GitHub Advisory | Reporter: prakhar0x01
CVE: CVE-2025-64491: XSS Vulnerability | GitHub Advisory | Reporter: Nicolas Decayeux (Patrowl)
PR: 10709 - Fix #10708 - Converting Quote to Invoice ignores field defaults
PR: 10713 - Fix #10713 - Fix edit link (pencil) in Global Search
PR: 10714 - Fix #10714 - Fix multienum fields in dashlet filters
PR: 10716 - Fix #10716 - Fix Inline Edit for decimal fields
PR: 10725 - Fix #10725 - Set Email Warning Notification to false
PR: 10571 - Fix #10570 - Email Signature Compose View Issues
PR: 10727 - Fix #10726 - Search Pagination and Module Filter
PR: 10733 - Fix #10732 - Can’t list view inbound email inboxes after soft-deleting a user with an active email inbox
PR: 10736 - Fix #10736 - Fix Workflow modify record date issue
PR: 10734 - Fix #10724 - Email Subject not importing correctly
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy
Released 06 August 2025
You are now able to configure an Outbound Email Account with OAuth. To see more information on setup please see here.
CVE: CVE-2025-54785: RCE Vulnerability | GitHub Advisory | Reporter: dzentota
CVE: CVE-2025-54786: Improper Access Control Vulnerability | GitHub Advisory | Reporter: sec31uk
CVE: CVE-2025-54787: Improper Access Control Vulnerability | GitHub Advisory | Reporter: paul1278
CVE: CVE-2025-54788: SQL Injection Vulnerability | GitHub Advisory | Reporter: Parnuski
CVE: CVE-2025-54783: XSS Vulnerability | GitHub Advisory | Reporter: Sergio Marín Martínez
CVE: CVE-2025-54784: XSS Vulnerability | GitHub Advisory | Reporter: paul1278
PR: 10599 - Fix Importing Error Styling
PR: 10565 - Fix #10564 - Thank you message in Surveys only in English
PR: 10549 - Fix variable name typo in getEmailInfo
PR: 10502 - Remove duplicate line
PR: 10480 - Fix #10479 - Call LoggerManager’s warn() method instead of warning()
PR: 10400 - Correctly find the id of related objects in search results
PR: 9810 - Fix #9809 - Incorrect parsing of 0 values in PDF templates
PR: 10660 - Fix Email Template not saving in plain text
PR: 10659 - Fix #10637 - Local users gets Profile wizard on each login
PR: 10309 - Fix #10264 - Error Assigned_user_name SearchView.tpl ({php} tag now crashes Smarty 4)
PR: 10476 - Fix #10475 - Rename the History subpanel by changing the label
PR: 10649 - Fix #8280 - Fix Autocomplete search in line items
PR: 10612 - Fix #10612 - Subpanels don’t show related records links when view permission is set to "group"
PR: 10607 - Fix #10606 - Recently viewed items tooltip shows module name instead of full record name
PR: 10625 - Fix #10624 - Prevent Multiple Submissions on Survey Forms
PR: 10538 - Fix #10243 - studio not saving field properties correctly
PR: 10285 - Fix non-countable error when importing CSV
PR: 10617 - Fix #10616 - Default values of DateTime always in English and value “first day of next month” gives an error
PR: 10648 - Fix #8632 - API V8 /meta/fields/{moduleName} endpoint output without field labels
PR: 10623 - Allow End Users to use the PATCH method for the V8 API
PR: 10601 - Fix #10113 - Contracts / List Items table for services has bogus width
PR: 10544 - Fix #10543 - Remove Security Groups button on subpanelsbased on EditView
PR: 10675 - Fix #10147, #10369 - Smarty unregistered function deprecated notice
PR: 10378 - Fix 10532, 10377 - Fix issues with global search not displaying values correctly
PR: 10700 - Fix #10345 - Azure OAuth Redirect Uri Entrypoint
Other Fixes:
Fix notice messages preventing importing.
Fix Importer progress bar using incorrect values.
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy
Released 05 November 2024
CVE: CVE-2024-50335: XSS Vulnerability | GitHub Advisory | Reporter: shellkraft
CVE: CVE-2024-49773: SQL Injection Vulnerability | GitHub Advisory | Reporter: dzentota
CVE: CVE-2024-50332: SQL Injection Vulnerability | GitHub Advisory | Reporter: amame04
CVE: CVE-2024-50333: RCE Vulnerability | GitHub Advisory | Reporter: dzentota
CVE: CVE-2024-49772: SQL Injection Vulnerability | GitHub Advisory | Reporter: LongHair00
CVE: CVE-2024-49774: RCE Vulnerability | GitHub Advisory | Reporter: dzentota
PR: 10520 - Fix #10520 - Discount Calculation incorrect when changing Currency
PR: 10451 - Fix #10450 - Add check for empty value before searching array
PR: 10523 - Fix #10503 - Item label in dropdown list is not displayed if it contains '<' character
PR: 10101 - Fix #10099 - Workflow action create record on CRON set incorrect date field values from related entity
PR: 10517 - Fix #507 - Calculated Fields - related field won’t show up as parameter
PR: 10225 - Fix #9036 - change log level according it message
PR: 10288 - Fix #9737 - issue with campaigns displaying a blank email template
PR: 10516 - Fix #10445 - Calendar: Calls still show even using Settings: 'Show Calls' = NO
PR: 10489 - Fix #10488 - Expand the number of filters in message queue views
PR: 10455 - Add scrollbars for Toolbox and Layout | Studio
PR: 10495 - Fix #9261 - Use decimal symbol configured in system and user
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy and send them directly to us via email security@suitecrm.com
Released 14 August 2024
There is a new configuration added to config.php called login_language. Setting this to true will show the language selector on login.
There is a new language selector in the User profile and User Wizard! Allowing any user to set their language via profile and setup.
This can be found within the Advanced tab.
Something to note: Logging in with a different language will set your Preference to that language.
CVE: CVE-2024-45392: Wrong deletion permission checks on API delete call | GitHub Advisory | Reporter: gunnicom
PR: 10469 - Fix #9177 - Cant use edit inline in UserType field
PR: 10468 - Fix #6376 - Problem with date start and finish in project task filters
PR: 10461 - Fix #10268 - Access token wil not refresh for Oauth2 password clients
PR: 10444 - Fix #10443 - Incorrect lengths in emails_text vardefs
PR: 10442 - Fix #10437 - Calendar - 'Today' left-hand side bar option loads the week
PR: 10434 - Fix #10433 - Email Address ID being double quoted
PR: 10429 - Fix #5653 - VAT Display in PDF Templates wrong when Currency Significant Digits set to 0
PR: 10406 - Fix #10404 - Compare parentenum_value more precisely
PR: 10399 - Fix #2175 - No gif and shifted text after saving task in gants view
PR: 10394 - Fix #2828 - Not translatable messages in Dashlet parameters
PR: 10390 - Fix #10390 - URL is not clickable
PR: 10373 - Fix #10372 - Product import fails with fatal error
PR: 10362 - Fix #9078 - Favorites adds record twice to the sidebar and to the db
PR: 10341 - Fix #10339 - Inconsistent application of trim function on name & varchar fields
PR: 10336 - Fix #10335 - Incorrect codification in the names of events displayed in the Calendar
PR: 10320 - Fix #10319 - Json API SQL error when filtering by custom fields
PR: 10470 - Fix #9829 - Fatal error during upgrade to 7.12.8
PR: 10441 - Fix #10441 - VAT Values display incorrectly on Quotes→Service Line Items, if Significant Figures = 0
PR: 10473 - Fix #9855 - Using a "Personal"-type Oauth Connection causes issues with "Group"-type Inbound Accounts
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy and send them directly to us via email security@suitecrm.com
Released 10 June 2024
We have updated our documentation regarding raising security issues, see more on that here.
We have updated recent SuiteCRM Version Release Notes with the Install and Upgrade Guide to both 7 and 8 as well as the Migration Guide for SuiteCRM 8.
Important: This release includes critical security fixes, we strongly recommend users of older versions to update as soon as possible
CVE: CVE-2024-36416: Excessive log data DOS Vulnerability | GitHub Advisory | Reporter: Elysee Franchuk
CVE: CVE-2024-36415: Improper Access Control Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36414: SSRF Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36413: XSS Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36412: SQL Injection Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36411: SQL Injection Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36410: SQL Injection Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36409: SQL Injection Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36408: SQL Injection Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36407: Improper Access Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36406: Open Redirect Vulnerability | GitHub Advisory | Reporter: Anael MURAT (Fidens) - Sicarius
CVE: CVE-2024-36418: RCE Vulnerability | GitHub Advisory | Reporter: Andrius Oželis
CVE: CVE-2023-6537: SSRF Vulnerability | GitHub Advisory | Reporter: Carlos Bello
CVE: CVE-2024-36419: Host Injection Vulnerability | GitHub Advisory | Reporter: Tanish Mahajan
PR: 10411 - Fix #10410 - Check report has been loaded before setting user params
PR: 9896 - Fix #9895 - Workflow - Copying Formatted values of a multienum to another field
PR: 9988 - Fix #9985 - Date end not stored correctly in Calls
PR: 10186 - Fix #10182 - Graphic Issue search view after 7.14 upgrade
PR: 9972 - Fix #9971 - Workflow - Add filters to quick and advanced search view in AOW Processed module
PR: 10322 - Fix #10321 - Creation of Project with Template Causes 500 Error
PR: 10328 - Fix #10327 - Survey Responses doesn’t get assigned_user after sending Survey
PR: 10375 - Fix #10375 - Upgradewizard double commit
PR: 10409 - Fix #10409 - skip to last page if disable_count_query=true
PR: 10323 - Fix #10172 - Emails don’t show subject MIME headers
PR: 10389 - Fix #1872 - Admin - Install Module - "Back to Module Loader" shows page with header only
PR: 10426 - Feature #10426 - new issue menu templates
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy and send them directly to us via email security@suitecrm.com
Released 05 February 2024
From this release forward there is a now an out of the box ElasticSearch Scheduler Job. The purpose of this job is to run an ElasticSearch Index. This will not be automatically added on upgrade due to backwards compatibility, however can be enabled via Admin page → Repair → Repair Schedulers.
PR: 10265 - Fix #5392 - My Filters doesn`t show up on Project Tasks
PR: 10295 - Fix #10242 - Mass Security Group Assignment fails when multiple items from the same page are chosen
PR: 10296 - Fix #10296 - Add duplication logic check on run_when Always
PR: 10297 - Fix #9453 - User 'delete' option missing from menu
PR: 10306 - Fix 5906 - Currency symbol for currency field in popup is always default
PR: 10301 - Fix 10234 - Enum-type fields may have their values reset to their defaults, if they have non-blank defaults
PR: 10299 - Fix #9853 - The "Case Macro" field now appears empty by Default
PR: 10312 - Fix #10312 - Group External Connection Changing type on edit
PR: 10313 - Fix #10313 - Remove unused line in repair
PR: 10293 - Fix 9858 - "Distribution Method" is not retained on Editview Load
PR: 10281 - Fix #10093 - Results are not filtered in the Targets Module popup
PR: 10278 - Fix #6397 - Studio: Reset Module: Remove Custom Fields
PR: 10314 - Fix #10314 - disabling active languages
PR: 10283 - Fix #10283 - When selecting an Outbound Email Account, From/Reply Information should autopopulate for user convenience
PR: 10308 - Fix #10307 - Retrieve object name via beanfactory
PR: 10275 - Fix #10207, #10209 - Multiple Elasticsearch indexing issues
Special thanks to the following members for their contributions and participation in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Policy and send them directly to us via email security@suitecrm.com
Released 14/11/2023
CVE: CVE-2023-6130 - LFI to RCE Vulnerability
CVE: CVE-2023-6128 - Reflected XSS Vulnerability
CVE: CVE-2023-6131 - Arbitrary File Upload to RCE
CVE: CVE-2023-6127 - Import XSS Vulnerability
CVE: CVE-2023-6126 - Dashlet HTML Injection Vulnerability
CVE: CVE-2023-6125 - PDF XSS Vulnerability
CVE: CVE-2023-6124 - SSRF Vulnerability
PR: 10253 - Fix #10252 - Google Maps Geocoded Counts not displaying properly
PR: 10248 - Fix #9537 - Activity subpanel isn’t working in a module with a parent_type / flex relate field
PR: 10241 - Fix #9898 - Invalid cookie domain when using non-standard HTTP Port
PR: 9522 - Fix #9435 - Dropdown doesn’t return empty selected value
PR: 10246 - Fix #10246 - non-admin’s outbound email link not showing
PR: 10220 - Fix #10220 - Add Email Body Filtering Selection
PR: 10212 - Fix #10199 - PHP Fatal error: Uncaught Error: Non-static method SugarWidgetReportField::_get_column_select()
PR: 10206 - Fix #10205 - Compatibility hotfix for PHP 8 in ActivitiesRelationship.php
PR: 10201 - Fix #9950 editing Email settings drops TLS SSL selection
PR: 10160 - Fix #10159 - Accounts - Not able to search by fax on 'Any Phone' search field
PR: 10143 - Fix #10143 - Update ready.php change checking of upload max filesize from > to >=
PR: 10122 - Fix #10115 - Wokflow Calculate Action broken under PHP8
PR: 10114 - Fix #10114 - parameter userTime method in class TimeDate
PR: 10049 - Fix #10049 - Relationship::delete expects a string
PR: 10028 - Fix #10028 - Allow workflow to send plain text emails
PR: 10027 - Fix #10027 - Respect wildcard in front when searching a full name in basic search
PR: 9881 - Fix #9880 - Error when importing currency fields with a decimal separator
PR: 9524 - Fix #9440 - Forcing default null value for numeric core fields
PR: 9459 - Fix #9456 - choose email provider does not populate SMTP settings
PR: 9413 - Fix #9412 - Wrong email value displayed when aborting an inline edition
Unify jquery versions
Special thanks to the following members for their contributions and participation in this release!
Special thanks to everyone who reported the security issues addressed in this release!
navsec, Christoph Timm, nam-no, Shahzaib Ali Khan, Alex Bernier
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Process and send them directly to us via email security@suitecrm.com
Released 03/10/2023
PR: 9806 - Fix #9805 - Use timezone offset for datetime only
PR: 9726 - Fix #9725 - Date field value isn’t saved in a Workflow action related module
PR: 10132 - Fix #10131 - Fix issue with file mode changes not being applied on cache rebuild
PR: 10110 - Fix #10109 - Add displayParams.initial_filter to Parent
PR: 9996 - Fix #8939 - Fix Static call to non-static method in AOW_WorkFlow
PR: 10005 - Fix #9574 - Avoid calling method in a static way
PR: 10058 - Fix #5390 - Redundant message when duplicating a survey
PR: 10130 - Fix #10129 - Fix issue with step 2 & 3 on the importer failing
PR: 10092 - Fix #9062 - Studio layout changes not being reflected
PR: 10016 - Fix #5712 - Alerts in the menu bar are not displayed with Night theme
PR: 10158 - Fix #10157 - Numbering display issue on subpanels
PR: 10064 - Fix #3842 - Vertical Scroll bar missing in Studio Layouts
PR: 10063 - Fix #2111 - Hover over favorites item, shows module name, not label
PR: 10079 - Fix #3050 - AOW: dropdown lists is not updating (calclulate field & modified record action)
PR: 9997 - Fix #8359 - Fix Contract renewal reminder title is hardcoded
PR: 10020 - Fix #10020 - Issue with missing label on Contact Module
PR: 10195 - Fix #10195 - dropdown keys are not the same type
PR: 10060 - Fix #10060 - User preferences detail-view template issues
PR: 10120 - Fix #10120 - Inbound Email Issues
PR: 9941 - Fix #9941 - Remove sugar pro flavor
Special thanks to everyone who reported security issues addressed in this release!
Josh Lees & Robert Stokes(Illume Security), Zilio Nicolas from CrowdStrike
Special thanks to the following members for their contributions and participation in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Process and send them directly to us via email security@suitecrm.com
Released 29/08/2023
The minimum php version has been updated to php 8.1. The supported versions are now php 8.1 and 8.2.
To visit the SuiteCRM 7.14.x Compatibility Matrix please see here.
Smarty, the templating engine used in SuiteCRM 7.x, has been upgraded to v4 which brings some minor performance improvements and better compatibility going forward.
This release brings a number of adjustments and updates in order to support PHP 8.2.
This includes:
Removal of deprecated functions/ features
Updated missing labels
Update functions to PHP 8.2 standard
Fixed Unit & Acceptance Tests
Executed Rector to clean up code
Fixed code to eliminate warnings from logs
Special thanks to the following members for their contributions and participation in this release!
Please visit the official website to find the appropriate upgrade package.
To report any security issues please follow our Security Process and send them directly to us via email security@suitecrm.com
Content is available under GNU Free Documentation License 1.3 or later unless otherwise noted.