Monicahq

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 20
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    16
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-26747

    Host Header Poisoning in Monica 4.1.2 Enables Phished Password Reset Links

    Last Modified: Apr 18, 2026
    Published: Feb 20, 2026

    CVE-2024-54951

    Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.

    Last Modified: Aug 14, 2025
    Published: Feb 13, 2025

    CVE-2024-54999

    MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

    Last Modified: Oct 07, 2025
    Published: Jan 13, 2025

    CVE-2024-54998

    MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

    Last Modified: May 07, 2025
    Published: Jan 10, 2025

    CVE-2024-54994

    MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

    Last Modified: May 07, 2025
    Published: Jan 10, 2025
    Items Per Page
    Monicahq Vulnerabilities & Security CVEs | CVE-DB