civicrm
Security Risk Profile
74
/100
highSecurity Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 6, 2012 to present
12
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
74/100
high
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
1High
3Medium
8Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
3
2
XSS
3
3
CSRF
2
4
Malicious File Upload
1
5
Code Injection
1
Most Affected Products
1. CiviCRM CiviCRM157
2. CiviCRM Civicrm Private Report Drupal5
3. Blair Williams Pretty Link Lite3
4. Caseproof Prettylinks3
5. composer/civicrm/civicrm-core2
Recent Vulnerabilities
See more →CVE-2026-72558
CVSS 8.8high
CiviCRM CiviCRM - SQL Injection
8/11/2026🔧 No Patch
CVE-2025-65187
CVSS 6.1medium
12/2/2025🔧 No Patch
CVE-2023-25440
CVSS 5.4medium
5/23/2023🔧 No Patch
CVE-2020-36388
CVSS 8.8high
6/17/2021🔧 No Patch
CVE-2020-36389
CVSS 4.3medium
6/17/2021🔧 No Patch
CVE-2018-1999022
CVSS 9.8critical
7/23/2018🔧 No Patch
CVE-2015-4391
CVSS 6.8medium
6/15/2015
CVE-2013-1636
CVSS 4.3medium
3/12/2014
CVE-2013-4661
CVSS 4.9medium
1/29/2014🔧 No Patch
CVE-2013-4662
CVSS 6.5medium
1/29/2014
Monitor civicrm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.