Skip to content

Known CVE

ChurchCRM 4.5.3 - Cross-Site Scripting

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

CVE-2023-26843

Medium2023CVSS 5.4CWE-79

cve2023 · churchcrm · stored-xss · xss · authenticated · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website