Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
civicrm civicrm vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2018-1999022
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_Q...
Html Quickform Project Html Quickform 3.2.14
Civicrm Civicrm 5.3.0
Civicrm Civicrm
7.5
CVSSv2
CVE-2013-5957
Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM prior to 4.2.12, 4.3.x prior to 4.3.7, and 4.4.x prior to 4.4.beta4 allow remote malicious users to execute arbitrary SQL commands via the _value parameter to (1) ajax/jqState or (2) ajax/jqcount...
Civicrm Civicrm 4.4.0
Civicrm Civicrm 4.4
Civicrm Civicrm
Civicrm Civicrm 4.2.10
Civicrm Civicrm 4.2.5
Civicrm Civicrm 4.2.4
Civicrm Civicrm 4.2.2
Civicrm Civicrm 4.2.1
Civicrm Civicrm 4.2.9
Civicrm Civicrm 4.2.7
Civicrm Civicrm 4.2.8
Civicrm Civicrm 4.2.6
Civicrm Civicrm 4.2.0
Civicrm Civicrm 4.3.3
Civicrm Civicrm 4.3.4
Civicrm Civicrm 4.3.5
Civicrm Civicrm 4.3.6
Civicrm Civicrm 4.3.1
Civicrm Civicrm 4.3.0
Civicrm Civicrm 4.3.2
6.8
CVSSv2
CVE-2015-4391
Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.3 for Drupal allows remote malicious users to hijack the authentication of users for requests that delete reports via unspecified vectors.
Civicrm Civicrm Private Report 7.x-1.2
Civicrm Civicrm Private Report 6.x-1.0
Civicrm Civicrm Private Report 6.x-1.1
Civicrm Civicrm Private Report 7.x-1.0
Civicrm Civicrm Private Report 7.x-1.1
6.5
CVSSv2
CVE-2020-36388
In CiviCRM prior to 5.21.3 and 5.22.x up to and including 5.24.x prior to 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Civicrm Civicrm
6.5
CVSSv2
CVE-2013-4662
The Quick Search API in CiviCRM 4.2.0 up to and including 4.2.9 and 4.3.0 up to and including 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to conta...
Civicrm Civicrm 4.2.8
Civicrm Civicrm 4.2.9
Civicrm Civicrm 4.3.1
Civicrm Civicrm 4.2.5
Civicrm Civicrm 4.2.7
Civicrm Civicrm 4.3.3
Civicrm Civicrm 4.2.0
Civicrm Civicrm 4.2.1
Civicrm Civicrm 4.2.2
Civicrm Civicrm 4.3.0
Civicrm Civicrm 4.3.2
Civicrm Civicrm 4.2.4
Civicrm Civicrm 4.2.6
5.8
CVSSv2
CVE-2011-5239
CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.
Civicrm Civicrm 4.1.1
Civicrm Civicrm 4.0.5
5
CVSSv2
CVE-2012-5554
The default configuration for the Webform CiviCRM Integration module 7.x-3.x prior to 7.x-3.2 has "Enforce Permissions" disabled, which allows remote malicious users to obtain contact information by reading webforms.
Coleman Watts Webform Civicrm 7.x-3.0
Coleman Watts Webform Civicrm 7.x-3.1
Coleman Watts Webform Civicrm 7.x-3.x
4.9
CVSSv2
CVE-2013-4661
CiviCRM 2.0.0 up to and including 4.2.9 and 4.3.0 up to and including 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intend...
Civicrm Civicrm 2.0.0
Civicrm Civicrm 2.2.1
Civicrm Civicrm 2.2.2
Civicrm Civicrm 2.2.3
Civicrm Civicrm 2.2.5
Civicrm Civicrm 3.1.4
Civicrm Civicrm 3.1.5
Civicrm Civicrm 3.1.6
Civicrm Civicrm 3.2.0
Civicrm Civicrm 4.3.1
Civicrm Civicrm 4.3.2
Civicrm Civicrm 4.3.3
Civicrm Civicrm 4.0.5
Civicrm Civicrm 4.2.7
Civicrm Civicrm 4.2.8
Civicrm Civicrm 4.2.9
Civicrm Civicrm 2.0.1
Civicrm Civicrm 2.0.3
Civicrm Civicrm 2.1.2
Civicrm Civicrm 2.1.6
Civicrm Civicrm 2.2.7
Civicrm Civicrm 2.2.9
4.3
CVSSv2
CVE-2020-36389
In CiviCRM prior to 5.28.1 and CiviCRM ESR prior to 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Civicrm Civicrm
4.3
CVSSv2
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin prior to 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 up to and including 4.2.9 and 4.3.0 u...
Blair Williams Pretty Link Lite 1.6.0
Blair Williams Pretty Link Lite 1.6.1
Blair Williams Pretty Link Lite
Joobi Com Jnews 8.0.1
Civicrm Civicrm 4.3.1
Civicrm Civicrm 3.1.1
Civicrm Civicrm 3.1.2
Civicrm Civicrm 3.2.2
Civicrm Civicrm 3.2.3
Civicrm Civicrm 3.3.6
Civicrm Civicrm 3.4.0
Civicrm Civicrm 4.1.5
Civicrm Civicrm 4.1.6
Civicrm Civicrm 4.2.7
Civicrm Civicrm 4.2.8
Civicrm Civicrm 4.3.3
Civicrm Civicrm 3.1.0
Civicrm Civicrm 3.2.0
Civicrm Civicrm 3.2.1
Civicrm Civicrm 3.3.3
Civicrm Civicrm 3.3.5
Civicrm Civicrm 4.1.3
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »