Products: 2
Vulnerabilities: 12
Known Exploited: 0
1
Critical Level Threats
3
High Level Threats
8
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-72558
CiviCRM CiviCRM - SQL Injection
Last Modified: Aug 11, 2026
Published: Aug 11, 2026
CVE-2025-65187
A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
Last Modified: Dec 23, 2025
Published: Dec 02, 2025
CVE-2023-25440
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
Last Modified: Jan 31, 2025
Published: May 23, 2023
CVE-2020-36388
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Last Modified: Nov 21, 2024
Published: Jun 17, 2021
CVE-2020-36389
In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.
Last Modified: Nov 21, 2024
Published: Jun 17, 2021
Items Per Page
