CVE-2024-54994: Monicahq Monica

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

Affected products

Published 2025-01-10. Last modified 2026-07-05.