Show filters
717 Total Results
Displaying 181-190 of 717
Sort by:
Attacker Value
Unknown
CVE-2023-31548
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2023-26842
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.
0
Attacker Value
Unknown
CVE-2023-2836
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-30253
Disclosure Date: May 29, 2023 (last updated February 25, 2025)
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
0
Attacker Value
Unknown
CVE-2023-2925
Disclosure Date: May 27, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-25976
Disclosure Date: May 26, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.
0
Attacker Value
Unknown
CVE-2023-25440
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
0
Attacker Value
Unknown
CVE-2023-31699
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.
0
Attacker Value
Unknown
CVE-2023-30185
Disclosure Date: May 08, 2023 (last updated February 24, 2025)
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
0
Attacker Value
Unknown
CVE-2023-29842
Disclosure Date: May 04, 2023 (last updated February 24, 2025)
ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.
0