Products: 2
    Vulnerabilities: 12
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-72558

    CiviCRM CiviCRM - SQL Injection

    Last Modified: Aug 11, 2026
    Published: Aug 11, 2026

    CVE-2025-65187

    A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.

    Last Modified: Dec 23, 2025
    Published: Dec 02, 2025

    CVE-2023-25440

    Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.

    Last Modified: Jan 31, 2025
    Published: May 23, 2023

    CVE-2020-36388

    In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

    Last Modified: Nov 21, 2024
    Published: Jun 17, 2021

    CVE-2020-36389

    In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.

    Last Modified: Nov 21, 2024
    Published: Jun 17, 2021
    Items Per Page
    Civicrm Vulnerabilities & Security CVEs | CVE-DB