Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
churchcrm churchcrm 4.5.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-33661
Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-31548
A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26842
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the OptionManager.php.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25346
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25347
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote malicious users to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25348
ChurchCRM 4.5.3 exists to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow malicious users to execute arbitrary code via a crafted excel file.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26839
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to edit information for existing people on the site.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26840
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to set a person to a user and set that user to be an Administrator.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26841
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to change any user's password except for the user that is currently logged in.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26843
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the NoteEditor.php.
Churchcrm Churchcrm 4.5.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
IMAP
CVE-2024-4367
server-side request forgery
information disclosure
CVE-2024-34342
CVE-2024-4281
CVE-2024-3507
CVE-2024-25560
CVE-2024-34574
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »