Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Civicrm MEDIUM 6.1
CVE-2025-65187

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious…

Fix: 6.7.0+
Fix from $1,600 2025-12-02
Civicrm MEDIUM 5.4
CVE-2023-25440

Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/…

No fix yet
Fix from $1,600 2023-05-23
Civicrm HIGH 8.8
CVE-2020-36388

In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

Fix: 5.21.3 / 5.24.3+
Fix from $1,950 2021-06-17
Civicrm Private Report MEDIUM 6.8
CVE-2015-4391

Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal all…

Patch available
Fix from $1,600 2015-06-15
Civicrm MEDIUM 6.5
CVE-2013-4662

The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and cond…

Mitigation only
Fix from $1,600 2014-01-29
Civicrm HIGH 7.5
CVE-2013-5957

Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 al…

Fix: after 4.2.11
Fix from $1,950 2013-11-27
Civicrm MEDIUM 5.8
CVE-2011-5239

CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

Mitigation only
Fix from $1,600 2012-11-06