10splayaSec
9 exploits
Active since Apr 2023
ChurchCRM 4.5.3 - Reflected Cross-Site Scripting via Family ID Parameter
CVSS 6.1
ChurchCRM 4.5.3 - Stored Cross-Site Scripting in Event Title Input Field
CVSS 5.4
ChurchCRM 4.5.3 - CSV Injection via Last Name and First Name Input Fields
CVSS 7.8
ChurchCRM 4.5.3 - Cross-Site Request Forgery
CVSS 4.3
ChurchCRM 4.5.3 - Cross-Site Request Forgery
CVSS 5.3
ChurchCRM 4.5.3 - Cross-Site Request Forgery
CVSS 6.5
ChurchCRM 4.5.3 - Stored Cross-Site Scripting via OptionManager.php
CVSS 5.4
ChurchCRM 4.5.3 - Stored Cross-Site Scripting via NoteEditor.php
CVSS 5.4
ChurchCRM 4.5.3 - Stored Cross-Site Scripting in FundRaiserEditor.php
CVSS 5.4