高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2026-39337 | 10.0 CRITICAL | ChurchCRM Affected by Unauthenticated RCE in Install Wizard |
| CVE-2026-35573 | 9.1 CRITICAL | ChurchCRM has a Path traversal leads to RCE |
| CVE-2026-39339 | 9.1 CRITICAL | ChurchCRM has an API Authentication Bypass |
| CVE-2026-39328 | 8.9 HIGH | ChurchCRM has Stored XSS in Social Profile Fields |
| CVE-2026-39326 | 8.8 HIGH | ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php |
| CVE-2026-39334 | 8.8 HIGH | ChurchCRM has a Blind SQL injection in SettingsIndividual.php |
| CVE-2026-39327 | 8.8 HIGH | ChurchCRM has a SQL injection in MemberRoleChange.php |
| CVE-2026-39319 | 8.8 HIGH | ChurchCRM has a Second Order SQLI via FundRaiserEditor.php |
| CVE-2026-39329 | 8.8 HIGH | ChurchCRM has a Blind SQL injection in EventNames.php |
| CVE-2026-39318 | 8.8 HIGH | ChurchCRM has a DDL SQL Injection in GroupPropsFormRowOps.php |
| CVE-2026-39330 | 8.8 HIGH | ChurchCRM has a Blind SQL injection in PropertyAssign.php |
| CVE-2026-35576 | 8.7 HIGH | ChurchCRM has Stored Cross-Site Scripting (XSS) in Person Properties via PrintView.php |
| CVE-2026-39333 | 8.7 HIGH | ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php |
| CVE-2026-39332 | 8.7 HIGH | ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php |
| CVE-2026-39340 | 8.1 HIGH | ChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer Substituti |
| CVE-2026-39341 | 8.1 HIGH | SQL injection in ChurchCRM.0 |
| CVE-2026-35575 | 8.0 HIGH | ChurchCRM has Stored XSS in Group Name |
| CVE-2026-35534 | 7.6 HIGH | ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection |
| CVE-2026-35574 | 7.3 HIGH | ChurchCRM has a Stored XSS in Person Profile - Add a Note |
| CVE-2026-39325 | 7.2 HIGH | ChurchCRM has a Blind SQL injection in SettingsUser.php |
Showing 20 of 28 CVEs. View all on vendor page →
まだコメントはありません