CVE-2024-54951: Monicahq Monica

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.

Affected products

Published 2025-02-13. Last modified 2026-06-17.