Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
monica vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2020-35660
Cross Site Scripting (XSS) in Monica prior to 2.19.1 via the journal page.
Monicahq Monica
5.4
CVSSv3
CVE-2023-30788
MonicaHQ version 4.0.0 allows an authenticated remote malicious user to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter.
Monicahq Monica 4.0.0
5.4
CVSSv3
CVE-2023-30789
MonicaHQ version 4.0.0 allows an authenticated remote malicious user to execute malicious code in the application via CSTI in the `people:id/work` endpoint and job and company parameter.
Monicahq Monica 4.0.0
5.4
CVSSv3
CVE-2023-30790
MonicaHQ version 4.0.0 allows an authenticated remote malicious user to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
Monicahq Monica 4.0.0
5.4
CVSSv3
CVE-2023-50465
A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.
Monicahq Monica 0.4.0
5.4
CVSSv3
CVE-2021-27368
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
Monicahq Monica 2.19.1
5.4
CVSSv3
CVE-2021-27369
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
Monicahq Monica 2.19.1
5.4
CVSSv3
CVE-2021-27371
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
Monicahq Monica 2.19.1
5.4
CVSSv3
CVE-2021-27559
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
Monicahq Monica 2.19.1
8.8
CVSSv3
CVE-2023-1031
MonicaHQ version 4.0.0 allows an authenticated remote malicious user to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.
Monicahq Monica 4.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »