Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Churchcrm HIGH 7.8
CVE-2023-25348

ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. The…

No fix yet
Fix from $1,950 2023-04-25
Churchcrm MEDIUM 6.1
CVE-2023-25346

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id par…

No fix yet
Fix from $1,600 2023-04-25
Churchcrm MEDIUM 5.4
CVE-2023-25347

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields…

No fix yet
Fix from $1,600 2023-04-25
Churchcrm MEDIUM 5.3
CVE-2023-26840

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administr…

No fix yet
Fix from $1,600 2023-04-25
Churchcrm HIGH 7.5
CVE-2023-26855

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attack…

No fix yet
Fix from $1,950 2023-04-04
Churchcrm MEDIUM 5.4
CVE-2023-27059

A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML v…

No fix yet
Fix from $1,600 2023-03-16
Churchcrm HIGH 7.2
CVE-2023-24684

ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.

Fix: after 4.5.3
Fix from $1,950 2023-02-09
Churchcrm HIGH 7.2
CVE-2023-24685

ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

Fix: after 4.5.3
Fix from $1,950 2023-02-09
Churchcrm MEDIUM 5.4
CVE-2023-24690

ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.

Fix: after 4.5.3
Fix from $1,600 2023-02-09
Churchcrm HIGH 7.2
CVE-2022-31325EPSS 5%

There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

No fix yet
Fix from $1,950 2022-06-08
Churchcrm HIGH 8.8
CVE-2021-41965

A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to t…

Fix: after 4.4.5
Fix from $1,950 2022-05-15