Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-65187 A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious… Civicrm 6.7.0+ Fix from $1,6002025-12-02 MEDIUM 5.4 CVE-2023-25440 Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/… Civicrm No fix yet Fix from $1,6002023-05-23 HIGH 8.8 CVE-2020-36388 In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive. Civicrm 5.21.3 / 5.24.3+ Fix from $1,9502021-06-17 MEDIUM 6.8 CVE-2015-4391 Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal all… Civicrm Private Report Patch available Fix from $1,6002015-06-15 MEDIUM 6.5 CVE-2013-4662 The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and cond… Civicrm Mitigation only Fix from $1,6002014-01-29 HIGH 7.5 CVE-2013-5957 Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 al… Civicrm after 4.2.11 Fix from $1,9502013-11-27 MEDIUM 5.8 CVE-2011-5239 CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t… Civicrm Mitigation only Fix from $1,6002012-11-06