Known Vulnerabilities for CiviCRM by CiviCRM
Listed below are 9 of the newest known vulnerabilities associated with "CiviCRM" by "CiviCRM".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72558 json | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the ... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2023-25440 json | Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute ... | 5.4 - MEDIUM | 2023-05-23 | 2023-05-30 |
| CVE-2020-36389 json | In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF. | 4.3 - MEDIUM | 2021-06-17 | 2023-02-03 |
| CVE-2020-36388 json | In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR arch... | 8.8 - HIGH | 2021-06-17 | 2023-02-03 |
| CVE-2018-1999022 json | PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue metho... | 9.8 - CRITICAL | 2018-07-23 | 2018-10-03 |
| CVE-2013-5957 json | Not Provided | 2013-11-27 | 2026-04-29 | |
| CVE-2013-4662 json | Not Provided | 2014-01-29 | 2026-04-29 | |
| CVE-2013-4661 json | Not Provided | 2014-01-29 | 2026-04-29 | |
| CVE-2013-1636 json | Not Provided | 2014-03-12 | 2026-05-06 | |
| CVE-2011-5239 json | Not Provided | 2012-11-06 | 2026-04-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Civicrm | Civicrm | 5.9.1 | |||
| Application | Civicrm | Civicrm | 5.9.0 | |||
| Application | Civicrm | Civicrm | 5.8.2 | |||
| Application | Civicrm | Civicrm | 5.8.1 | |||
| Application | Civicrm | Civicrm | 5.8.0 | |||
| Application | Civicrm | Civicrm | 5.7.3 | |||
| Application | Civicrm | Civicrm | 5.7.2 | |||
| Application | Civicrm | Civicrm | 5.7.1 | |||
| Application | Civicrm | Civicrm | 5.7.0 | |||
| Application | Civicrm | Civicrm | 5.6.1 | |||
| Application | Civicrm | Civicrm | 5.6.0 | |||
| Application | Civicrm | Civicrm | 5.5.3 | |||
| Application | Civicrm | Civicrm | 5.5.2 | |||
| Application | Civicrm | Civicrm | 5.5.1 | |||
| Application | Civicrm | Civicrm | 5.5.0 | |||
| Application | Civicrm | Civicrm | 5.4.1 | |||
| Application | Civicrm | Civicrm | 5.4.0 | |||
| Application | Civicrm | Civicrm | 5.34.0 | |||
| Application | Civicrm | Civicrm | 5.33.2 | |||
| Application | Civicrm | Civicrm | 5.33.1 |