Vulnerabilities > Civicrm > Civicrm > 4.4.0

DATE CVE VULNERABILITY TITLE RISK
2021-06-17 CVE-2020-36388 Unrestricted Upload of File with Dangerous Type vulnerability in Civicrm
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
network
low complexity
civicrm CWE-434
8.8
2018-07-23 CVE-2018-1999022 Code Injection vulnerability in multiple products
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method.
network
low complexity
html-quickform-project civicrm CWE-94
7.5
2013-11-27 CVE-2013-5957 SQL Injection vulnerability in Civicrm
Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 allow remote attackers to execute arbitrary SQL commands via the _value parameter to (1) ajax/jqState or (2) ajax/jqcounty.
network
low complexity
civicrm CWE-89
7.5