Monicahq is a specialized personal relationship-management application that, despite a narrow product scope, occupies a more prominent position in the vulnerability landscape than typical for its category. Vulnerabilities affecting the vendor concentrate in the Monica application itself and recur through web-application weakness classes including cross-site scripting, code injection, and HTTP header neutralization issues that are characteristic of server-side web frameworks. The exposure profile reflects the application's role as a server-side service handling user data and request processing, where input validation and output encoding defenses must operate across multiple attack surfaces. Defenders deploying Monica should maintain attention to application-layer patching and validate deployment isolation practices; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monicahq over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26747CRITICAL A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default mis | Feb 20, 2026 | 9.1 | 28 | NO | NO |
CVE-2021-27370MEDIUM The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. | Feb 22, 2021 | 5.4 | 28 | NO | YES |
CVE-2024-54996HIGH MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create. | Jan 10, 2025 | 8.8 | 26 | NO | NO |
CVE-2023-1094HIGH MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter. | May 8, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-1031HIGH MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter. | May 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-54994MEDIUM MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature. | Jan 10, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-54999MEDIUM MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module. | Jan 13, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-54998MEDIUM MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create. | Jan 10, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-54997MEDIUM MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit. | Jan 10, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-30790MEDIUM MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and la | May 8, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monicahq.
Media articles that mention a CVE ID that affects a product developed by Monicahq — matched by CVE ID, not by vendor name.