c
civicrm
Security Risk Profile
74
/100
highSecurity Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 6, 2012 to present
12
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
74/100
high
📈 1 in Last 30 Days
Severity Distribution
Critical
1High
3Medium
8Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
3
2
XSS
3
3
CSRF
2
4
Malicious File Upload
1
5
Code Injection
1
Most Affected Products
1. CiviCRM CiviCRM157
2. CiviCRM Civicrm Private Report Drupal5
3. Blair Williams Pretty Link Lite3
4. Caseproof Prettylinks3
5. composer/civicrm/civicrm-core2
Recent Vulnerabilities
See more →CVE-2026-72558
CVSS 8.8high
CiviCRM CiviCRM - SQL Injection
Aug 11, 2026🔧 No Patch
CVE-2025-65187
CVSS 6.1medium
Dec 2, 2025🔧 No Patch
CVE-2023-25440
CVSS 5.4medium
May 23, 2023🔧 No Patch
CVE-2020-36388
CVSS 8.8high
Jun 17, 2021🔧 No Patch
CVE-2020-36389
CVSS 4.3medium
Jun 17, 2021🔧 No Patch
CVE-2018-1999022
CVSS 9.8critical
Jul 23, 2018🔧 No Patch
CVE-2015-4391
CVSS 6.8medium
Jun 15, 2015
CVE-2013-1636
CVSS 4.3medium
Mar 12, 2014
CVE-2013-4661
CVSS 4.9medium
Jan 29, 2014🔧 No Patch
CVE-2013-4662
CVSS 6.5medium
Jan 29, 2014
Monitor civicrm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.