📦 Monica

by Monicahq

🔍 What is Monica?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-54996

HIGH CVSS 8.8 Jan 10, 2025

MonicaHQ v4.1.2 contains authenticated client-side injection vulnerabilities in the title and description parameters of the reminders creation feature. This allows authenticated attackers to inject ma...

CVE-2023-1031

HIGH CVSS 8.8 May 8, 2023

MonicaHQ 4.0.0 contains a client-side template injection (CSTI) vulnerability in the settings endpoint's first_name parameter that allows authenticated attackers to execute malicious JavaScript code. ...

CVE-2024-54951

MEDIUM CVSS 5.4 Feb 13, 2025

Monica 4.1.2 contains a stored cross-site scripting (XSS) vulnerability in the 'HOW YOU MET' contact customization feature. An authenticated attacker can create malicious contacts that execute JavaScr...

CVE-2024-54997

MEDIUM CVSS 5.4 Jan 10, 2025

MonicaHQ v4.1.1 contains an authenticated client-side injection vulnerability in the journal entry text field. This allows authenticated attackers to inject malicious scripts that execute in other use...