Known CVE
ChurchCRM 4.5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.
CVE-2023-26843
Medium2023CVSS 5.4CWE-79
cve2023 · churchcrm · stored-xss · xss · authenticated · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website