Total CVEs

125,880

Critical Severity

2,277

High Severity

7,888

Last 7 Days

1,158
Quick preset (or use dates below)
Clear Filters
Showing 61 - 80 of 612 CVEs
CVE-2026-35573 CRITICAL - 9.1

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. T...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35572 MEDIUM - 6.0

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (SSRF) by supplying a crafted URL in the Referer request header. The server subsequently makes an outbound request to the attacker-controlled domain, con...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD

ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a link that, when visited by an authenticated user, would redirect them to any URL chosen by an attacker if they clicked 'Cancel' button on the pa...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35574 HIGH - 7.3

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authenticated users with note-adding permissions to execute arbitrary JavaScript code in the context of other users' browsers, including...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35567 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, the NewRole POST parameter in src/MemberRoleChange.php is used in an SQL query without proper integer validation, allowing authenticated users to inject arbitrary SQL. The attack requires an authenticated session with ManageGroups...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35566 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical SQL injection vulnerability exists in src/Reports/FundRaiserStatement.php where the $_SESSION['iCurrentFundraiser'] value is used in an unquoted numeric SQL context without integer validation. The value origin...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35534 HIGH - 7.6

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute context. The function only strips HTML tags, it does not escape quote characters...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-22666 HIGH - 7.2

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35184 CRITICAL - 9.8

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

Vendor: phili67
Product: ecclesiacrm
Published: Apr 06, 2026
Source: NVD
CVE-2026-34402 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, authenticated users with Edit Records or Manage Groups permissions can exploit a time-based blind SQL injection vulnerability in the PropertyAssign.php endpoint to exfiltrate or modify any database content, including user credenti...

Vendor: ChurchCRM
Product: CRM
Published: Apr 06, 2026
Source: NVD
CVE-2019-25664 HIGH - 7.1

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extra...

Vendor: Suitecrm
Product: SuiteCRM
Published: Apr 05, 2026
Source: NVD
CVE-2019-25663 HIGH - 7.1

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techn...

Vendor: Suitecrm
Product: SuiteCRM
Published: Apr 05, 2026
Source: NVD
CVE-2026-5370 LOW - 3.5

A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the att...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34036 MEDIUM - 6.5

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploit...

Vendor: composer
Product: dolibarr/dolibarr
Published: Mar 27, 2026
Source: GitHub
CVE-2026-32527 MEDIUM - 6.5

Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-insightly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Insightly for Contact Form 7, WPForms, Elementor, Formidable an...

Vendor: CRM Perks
Product: WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
Published: Mar 25, 2026
Source: NVD
CVE-2026-25430 MEDIUM - 6.5

Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ni...

Vendor: CRM Perks
Product: Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Published: Mar 25, 2026
Source: NVD
CVE-2026-3567 MEDIUM - 5.3

The RepairBuddy โ€“ Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings. First, the wc_rb_get_f...

Published: Mar 21, 2026
Source: NVD
CVE-2026-32880 MEDIUM - 6.4

ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaScript payload that can execute when any admin views the system settings. The JSON input is left unescaped/unsanitized in SystemSettings.php, leading to ...

Vendor: ChurchCRM
Product: CRM
Published: Mar 20, 2026
Source: NVD
CVE-2026-33289 HIGH - 8.8

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied input before embedding it...

Vendor: SuiteCRM
Product: SuiteCRM
Published: Mar 20, 2026
Source: NVD
CVE-2026-33288 HIGH - 8.8

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails to properly sanitize t...

Vendor: SuiteCRM
Product: SuiteCRM
Published: Mar 20, 2026
Source: NVD