Vulnerabilities > Civicrm > Civicrm > 5.16.2

DATE CVE VULNERABILITY TITLE RISK
2021-06-17 CVE-2020-36388 Unrestricted Upload of File with Dangerous Type vulnerability in Civicrm
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
network
low complexity
civicrm CWE-434
8.8