Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Churchcrm CRITICAL 9.8
CVE-2024-53438

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' paramet…

Mitigation only
Fix from $2,300 2024-11-22
Churchcrm MEDIUM 5.4
CVE-2024-36647

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloa…

No fix yet
Fix from $1,600 2024-06-13
Churchcrm CRITICAL 9.8
CVE-2024-25894

ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

No fix yet
Fix from $2,300 2024-02-21
Churchcrm CRITICAL 9.8
CVE-2024-25897

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

No fix yet
Fix from $2,300 2024-02-21
Churchcrm CRITICAL 9.1
CVE-2024-25893

ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

No fix yet
Fix from $2,300 2024-02-21
Churchcrm HIGH 8.1
CVE-2024-25892

ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.

No fix yet
Fix from $1,950 2024-02-21
Churchcrm HIGH 7.5
CVE-2024-25891

ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

No fix yet
Fix from $1,950 2024-02-21
Churchcrm MEDIUM 6.1
CVE-2024-25895

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type p…

No fix yet
Fix from $1,600 2024-02-21
Churchcrm MEDIUM 6.1
CVE-2024-25898

A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event S…

No fix yet
Fix from $1,600 2024-02-21
Churchcrm MEDIUM 5.3
CVE-2024-25896

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

No fix yet
Fix from $1,600 2024-02-21
Churchcrm HIGH 8.8
CVE-2020-28848

CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.

No fix yet
Fix from $1,950 2023-08-11
Churchcrm HIGH 7.5
CVE-2023-38768

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the PropertyID parameter within the /Qu…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38769

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat paramet…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38770

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryVi…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38771

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryV…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38773

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters with…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38760

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the role and gender parameters within t…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38762

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38764

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the birthmonth and percls parameters wi…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38765

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the membermonth parameter within the /Q…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm HIGH 7.5
CVE-2023-38767

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value' and 'custom' parameters wit…

Mitigation only
Fix from $1,950 2023-08-08
Churchcrm MEDIUM 6.5
CVE-2023-38763

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the FundRaiserID parameter within the /…

Mitigation only
Fix from $1,600 2023-08-08
Churchcrm MEDIUM 6.1
CVE-2023-38761

Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the systemS…

Mitigation only
Fix from $1,600 2023-08-08
Churchcrm MEDIUM 5.4
CVE-2023-38766

Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonV…

Mitigation only
Fix from $1,600 2023-08-08
Churchcrm MEDIUM 6.1
CVE-2023-33661

Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart…

No fix yet
Fix from $1,600 2023-06-29
Churchcrm MEDIUM 5.4
CVE-2023-26842

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionMan…

No fix yet
Fix from $1,600 2023-05-31
Churchcrm MEDIUM 5.4
CVE-2023-31548

A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2023-05-31
Churchcrm HIGH 8.8
CVE-2023-29842

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

No fix yet
Fix from $1,950 2023-05-04
Churchcrm MEDIUM 6.5
CVE-2023-26841

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is curr…

No fix yet
Fix from $1,600 2023-04-25
Churchcrm MEDIUM 5.4
CVE-2023-26843

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEdito…

No fix yet
Fix from $1,600 2023-04-25