Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-25348 ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. The… Churchcrm No fix yet Fix from $1,9502023-04-25 MEDIUM 6.1 CVE-2023-25346 A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id par… Churchcrm No fix yet Fix from $1,6002023-04-25 MEDIUM 5.4 CVE-2023-25347 A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields… Churchcrm No fix yet Fix from $1,6002023-04-25 MEDIUM 5.3 CVE-2023-26840 A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administr… Churchcrm No fix yet Fix from $1,6002023-04-25 HIGH 7.5 CVE-2023-26855 The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attack… Churchcrm No fix yet Fix from $1,9502023-04-04 MEDIUM 5.4 CVE-2023-27059 A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML v… Churchcrm No fix yet Fix from $1,6002023-03-16 HIGH 7.2 CVE-2023-24684 ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php. Churchcrm after 4.5.3 Fix from $1,9502023-02-09 HIGH 7.2 CVE-2023-24685 ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module. Churchcrm after 4.5.3 Fix from $1,9502023-02-09 MEDIUM 5.4 CVE-2023-24690 ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family. Churchcrm after 4.5.3 Fix from $1,6002023-02-09 HIGH 7.2 CVE-2022-31325EPSS 5% There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. Churchcrm No fix yet Fix from $1,9502022-06-08 HIGH 8.8 CVE-2021-41965 A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to t… Churchcrm after 4.4.5 Fix from $1,9502022-05-15