Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/civicrm/civicrm-core |
|
Tue, 11 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Civicrm
Civicrm civicrm |
|
| Vendors & Products |
Civicrm
Civicrm civicrm |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records. | |
| Title | CiviCRM CiviCRM - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:23:07.453Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72558
Updated: 2026-08-11T12:23:02.717Z
Status : Received
Published: 2026-08-11T12:17:41.697
Modified: 2026-08-11T13:19:03.143
Link: CVE-2026-72558
No data.
OpenCVE Enrichment
Updated: 2026-08-11T18:15:07Z