Show filters
717 Total Results
Displaying 211-220 of 717
Sort by:
Attacker Value
Unknown

CVE-2023-24690

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.
Attacker Value
Unknown

CVE-2023-24686

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
Attacker Value
Unknown

CVE-2023-24685

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.
Attacker Value
Unknown

CVE-2023-24684

Disclosure Date: February 09, 2023 (last updated February 24, 2025)
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
Attacker Value
Unknown

CVE-2022-44343

Disclosure Date: February 06, 2023 (last updated February 24, 2025)
CRMEB 4.4.4 is vulnerable to Any File download.
Attacker Value
Unknown

CVE-2022-48082

Disclosure Date: February 02, 2023 (last updated February 24, 2025)
Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.
Attacker Value
Unknown

CVE-2022-47073

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.
Attacker Value
Unknown

CVE-2022-38467

Disclosure Date: January 14, 2023 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
Attacker Value
Unknown

CVE-2022-46610

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-4497

Disclosure Date: January 09, 2023 (last updated October 08, 2023)
The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins