Show filters
717 Total Results
Displaying 211-220 of 717
Sort by:
Attacker Value
Unknown
CVE-2023-24690
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.
0
Attacker Value
Unknown
CVE-2023-24686
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
0
Attacker Value
Unknown
CVE-2023-24685
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.
0
Attacker Value
Unknown
CVE-2023-24684
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
0
Attacker Value
Unknown
CVE-2022-44343
Disclosure Date: February 06, 2023 (last updated February 24, 2025)
CRMEB 4.4.4 is vulnerable to Any File download.
0
Attacker Value
Unknown
CVE-2022-48082
Disclosure Date: February 02, 2023 (last updated February 24, 2025)
Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.
0
Attacker Value
Unknown
CVE-2022-47073
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.
0
Attacker Value
Unknown
CVE-2022-38467
Disclosure Date: January 14, 2023 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
0
Attacker Value
Unknown
CVE-2022-46610
Disclosure Date: January 10, 2023 (last updated February 24, 2025)
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-4497
Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins
0