monicahq CVE Vulnerabilities & CVE List (20)

Products (CPE): — CVEs: 20

monicahq vulnerability overview

Aggregates CVE and security vulnerability intelligence across all monicahq-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface production workloads and vendor surface software deployment contexts.

Vulnerability distribution trend (last 24 months)

Showing 120 of 20 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-26747 A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in password reset emails) using the user-supplied Host header. This allows remote attackers to poison the password reset link sent to a victim, [email protected] 9.1 0.05% 2026-02-20 2026-02-26
CVE-2024-54951 Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS. [email protected] 5.4 0.54% 2025-02-13 2025-08-14
CVE-2024-54999 MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module. [email protected] 6.5 0.05% 2025-01-13 2025-10-07
CVE-2024-54998 MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create. [email protected] 5.4 0.09% 2025-01-10 2025-05-07
CVE-2024-54997 MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit. [email protected] 5.4 0.44% 2025-01-10 2025-05-07
CVE-2024-54996 MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create. [email protected] 8.8 0.18% 2025-01-10 2025-05-07
CVE-2024-54994 MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature. [email protected] 6.5 0.35% 2025-01-10 2025-05-07
CVE-2023-50465 A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user. [email protected] 5.4 0.12% 2023-12-11 2024-11-21
CVE-2023-30790 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter. [email protected] 5.4 0.26% 2023-05-08 2025-02-03
CVE-2023-30789 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/work` endpoint and job and company parameter. [email protected] 5.4 0.24% 2023-05-08 2025-02-03
CVE-2023-30788 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter. [email protected] 5.4 0.38% 2023-05-08 2025-02-04
CVE-2023-30787 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introductions` endpoint and first_met_additional_info parameter. [email protected] 5.4 0.23% 2023-05-08 2025-02-03
CVE-2023-1094 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter. [email protected] 8.8 0.84% 2023-05-08 2025-01-29
CVE-2023-1031 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter. [email protected] 8.8 1.14% 2023-05-08 2025-01-29
CVE-2020-35660 Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page. [email protected] 5.4 0.26% 2021-04-14 2024-11-21
CVE-2021-27559 The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field. [email protected] 5.4 0.19% 2021-02-22 2024-11-21
CVE-2021-27371 The Contact page in Monica 2.19.1 allows stored XSS via the Description field. [email protected] 5.4 0.17% 2021-02-22 2024-11-21
CVE-2021-27370 The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. [email protected] 5.4 0.30% 2021-02-22 2024-11-21
CVE-2021-27369 The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field. [email protected] 5.4 0.19% 2021-02-22 2024-11-21
CVE-2021-27368 The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. [email protected] 5.4 0.19% 2021-02-22 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence