Debian Package Tracker
Register | Log in
Subscribe

civicrm

Choose email to subscribe with

general
  • source: civicrm (main)
  • version: 5.33.2+dfsg1-1
  • maintainer: Dmitry Smirnov (DMD)
  • arch: all
  • std-ver: 4.5.0
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.33.2+dfsg1-1
versioned links
  • 5.33.2+dfsg1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • civicrm-common
  • civicrm-l10n
  • wordpress-civicrm
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
6 security issues in bullseye high

There are 6 open security issues in bullseye.

1 important issue:
  • CVE-2026-72558: An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
5 issues postponed or untriaged:
  • CVE-2025-3573: (postponed; to be fixed through a stable update) Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
  • CVE-2021-21252: (needs triaging) The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
  • CVE-2023-25440: (needs triaging) Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
  • CVE-2023-28115: (needs triaging) Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.4.2, Snappy is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the `file_exists()` function. If an attacker can upload files of any type to the server he can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution especially when snappy is used with frameworks with documented POP chains like Laravel/Symfony vulnerable developer code. If a user can control the output file from the `generateFromHtml()` function, it will invoke deserialization. This vulnerability is capable of remote code execution if Snappy is used with frameworks or developer code with vulnerable POP chains. It has been fixed in version 1.4.2.
  • CVE-2025-65187: (postponed; to be fixed through a stable update) A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
Created: 2026-08-12 Last update: 2026-08-12 09:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-3573: Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.
Created: 2025-04-17 Last update: 2025-08-10 06:32
news
[rss feed]
  • [2025-10-16] Removed 5.68.1+dfsg1-1 from unstable (Debian FTP Masters)
  • [2024-09-19] civicrm REMOVED from testing (Debian testing watch)
  • [2024-01-10] civicrm 5.68.1+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-05] Accepted civicrm 5.68.1+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2023-06-13] civicrm 5.53.0+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2023-03-21] civicrm REMOVED from testing (Debian testing watch)
  • [2023-02-09] civicrm 5.53.0+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-29] Accepted civicrm 5.53.0+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2022-08-16] Accepted civicrm 5.52.2+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2022-06-21] Accepted civicrm 5.50.3+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2022-06-11] Accepted civicrm 5.50.1+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2022-01-30] civicrm REMOVED from testing (Debian testing watch)
  • [2021-01-24] civicrm 5.33.2+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-19] Accepted civicrm 5.33.2+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2021-01-16] civicrm 5.33.1+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-11] Accepted civicrm 5.33.1+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2021-01-11] civicrm 5.28.4+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-05] Accepted civicrm 5.28.4+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2020-07-30] civicrm REMOVED from testing (Debian testing watch)
  • [2020-05-19] civicrm 5.25.0+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-14] Accepted civicrm 5.25.0+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2020-05-11] civicrm 5.24.6+dfsg1-2 MIGRATED to testing (Debian testing watch)
  • [2020-05-05] Accepted civicrm 5.24.6+dfsg1-2 (source) into unstable (Dmitry Smirnov)
  • [2020-05-03] Accepted civicrm 5.24.6+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2020-05-01] Accepted civicrm 5.24.5+dfsg1-1 (source) into unstable (Dmitry Smirnov)
  • [2020-02-20] Accepted civicrm 5.22.1+dfsg1-1 (source) into experimental (Dmitry Smirnov)
  • [2020-02-14] Accepted civicrm 5.22.0+dfsg1-1 (source) into experimental (Dmitry Smirnov)
  • [2020-02-03] civicrm 5.21.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-01-29] Accepted civicrm 5.21.2+dfsg-1 (source) into unstable (Dmitry Smirnov)
  • [2020-01-18] civicrm 5.21.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • security tracker

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing