📦 Churchcrm

by Churchcrm

🔍 What is Churchcrm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-68112

CRITICAL CVSS 9.6 Dec 17, 2025

ChurchCRM versions before 6.5.3 contain a SQL injection vulnerability in the Event Attendee Editor that allows authenticated users to execute arbitrary SQL commands. This can lead to complete database...

CVE-2025-68109

CRITICAL CVSS 9.1 Dec 17, 2025

ChurchCRM versions before 6.5.3 have a critical vulnerability in the Database Restore functionality that allows attackers to upload malicious files without validation. This enables remote code executi...

CVE-2025-68110

CRITICAL CVSS 9.9 Dec 17, 2025

ChurchCRM versions before 6.5.3 expose sensitive database credentials in error messages, allowing attackers to obtain database host, IP, username, and password. This affects all ChurchCRM installation...

CVE-2025-62521

CRITICAL CVSS 10.0 Dec 17, 2025

CVE-2025-62521 is a critical pre-authentication remote code execution vulnerability in ChurchCRM that allows unauthenticated attackers to inject arbitrary PHP code during the initial setup process. Th...

CVE-2025-1023

CRITICAL CVSS 9.8 Feb 18, 2025

A critical SQL injection vulnerability in ChurchCRM versions 5.13.0 and earlier allows attackers to execute arbitrary database queries through the EditEventTypes functionality. Attackers can manipulat...

CVE-2024-53438

CRITICAL CVSS 9.8 Nov 22, 2024

CVE-2024-53438 is a critical SQL injection vulnerability in ChurchCRM 5.7.0 that allows attackers to execute arbitrary SQL commands by manipulating the 'Event' parameter. This affects all ChurchCRM 5....

CVE-2024-25893

CRITICAL CVSS 9.1 Feb 21, 2024

ChurchCRM 5.5.0 contains a blind SQL injection vulnerability in FRCertificates.php via the CurrentFundraiser GET parameter. This allows attackers to execute arbitrary SQL queries and potentially extra...

CVE-2024-25897

CRITICAL CVSS 9.8 Feb 21, 2024

ChurchCRM 5.5.0 contains a blind SQL injection vulnerability in FRCatalog.php via the CurrentFundraiser GET parameter. Attackers can exploit this to extract database information or potentially execute...

CVE-2026-24854

HIGH CVSS 8.8 Jan 30, 2026

A SQL injection vulnerability in ChurchCRM allows any authenticated user, even with zero permissions, to execute arbitrary SQL commands through the PaddleNumEditor.php endpoint. This could lead to dat...

CVE-2025-68400

HIGH CVSS 8.8 Dec 17, 2025

A SQL injection vulnerability in ChurchCRM allows authenticated users with any permission level to execute arbitrary SQL commands through the familyId parameter in the legacy ConfirmReportEmail.php en...

CVE-2025-68111

HIGH CVSS 7.2 Dec 17, 2025

ChurchCRM versions before 6.5.3 contain a SQL injection vulnerability in the eGive.php file's ReImport functionality. Authenticated users with finance privileges can execute arbitrary SQL queries by m...

CVE-2025-67877

HIGH CVSS 8.8 Dec 17, 2025

CVE-2025-67877 is a SQL injection vulnerability in ChurchCRM versions before 6.5.3 that allows attackers to execute arbitrary SQL commands through the PersonAddress parameter. This affects all ChurchC...

CVE-2025-66397

HIGH CVSS 8.3 Dec 17, 2025

This vulnerability allows any authenticated user in ChurchCRM to perform Kiosk Manager actions like allowing/accepting kiosk registrations, reloading kiosks, and identifying kiosks. It affects all Chu...

CVE-2025-66396

HIGH CVSS 7.2 Dec 17, 2025

This SQL injection vulnerability in ChurchCRM allows malicious or compromised administrator accounts to execute arbitrary SQL commands. Attackers can directly manipulate the database to exfiltrate, mo...

CVE-2025-66395

HIGH CVSS 8.8 Dec 17, 2025

ChurchCRM versions before 6.5.3 contain a SQL injection vulnerability in the ListEvents.php file. Any authenticated user, regardless of privilege level, can execute arbitrary SQL commands to exfiltrat...

CVE-2025-67751

HIGH CVSS 7.2 Dec 16, 2025

ChurchCRM versions before 6.5.0 contain a SQL injection vulnerability in the EventEditor.php file. Authenticated users with event management permissions can exploit this by injecting malicious SQL thr...

CVE-2025-66313

HIGH CVSS 7.2 Dec 1, 2025

ChurchCRM versions 6.2.0 and earlier contain a time-based blind SQL injection vulnerability in the 1FieldSec parameter handling. This allows attackers to extract sensitive database information or modi...

CVE-2025-1132

HIGH CVSS 8.8 Feb 19, 2025

A time-based blind SQL injection vulnerability in ChurchCRM versions 5.13.0 and earlier allows authenticated administrators to execute arbitrary SQL commands via the EN_tyid parameter in EditEventAtte...

CVE-2025-1133

HIGH CVSS 7.2 Feb 19, 2025

This vulnerability allows authenticated administrators in ChurchCRM versions 5.13.0 and earlier to execute arbitrary SQL queries through boolean-based blind SQL injection in the EditEventAttendees fun...

CVE-2025-1134

HIGH CVSS 7.2 Feb 19, 2025

This SQL injection vulnerability in ChurchCRM allows attackers with administrator privileges to execute arbitrary SQL queries through the DonatedItemEditor functionality. It affects ChurchCRM versions...

CVE-2025-1135

HIGH CVSS 7.2 Feb 19, 2025

This SQL injection vulnerability in ChurchCRM allows attackers with administrator privileges to execute arbitrary SQL queries through the BatchWinnerEntry functionality. The vulnerability affects Chur...

CVE-2024-39304

HIGH CVSS 8.8 Jul 26, 2024

ChurchCRM versions before 5.9.2 contain an authenticated SQL injection vulnerability in the GetText.php endpoint. Attackers with any valid user account can inject malicious SQL through the EID paramet...

CVE-2024-25891

HIGH CVSS 7.5 Feb 21, 2024

ChurchCRM 5.5.0 contains a blind SQL injection vulnerability in FRBidSheets.php via the CurrentFundraiser GET parameter. This allows attackers to execute arbitrary SQL queries and potentially extract ...

CVE-2023-38769

HIGH CVSS 7.5 Aug 8, 2023

This SQL injection vulnerability in ChurchCRM v5.0.0 allows remote attackers to execute arbitrary SQL commands via the searchstring and searchwhat parameters in QueryView.php. This can lead to unautho...

CVE-2023-38771

HIGH CVSS 7.5 Aug 8, 2023

This SQL injection vulnerability in ChurchCRM v5.0.0 allows remote attackers to extract sensitive database information by manipulating the volopp parameter in QueryView.php. All organizations running ...

CVE-2023-38762

HIGH CVSS 7.5 Aug 8, 2023

A SQL injection vulnerability in ChurchCRM v5.0.0 allows remote attackers to extract sensitive database information by manipulating the friendmonths parameter in QueryView.php. This affects all Church...

CVE-2023-38764

HIGH CVSS 7.5 Aug 8, 2023

CVE-2023-38764 is an SQL injection vulnerability in ChurchCRM v5.0.0 that allows remote attackers to extract sensitive database information by manipulating birthmonth and percls parameters in QueryVie...

CVE-2023-38767

HIGH CVSS 7.5 Aug 8, 2023

This SQL injection vulnerability in ChurchCRM v5.0.0 allows remote attackers to execute arbitrary SQL commands via the 'value' and 'custom' parameters in QueryView.php. Attackers can potentially acces...

CVE-2023-29842

HIGH CVSS 8.8 May 4, 2023

ChurchCRM 4.5.4 contains a blind SQL injection vulnerability in the EditEventTypes.php endpoint via the EN_tyid POST parameter. Attackers can exploit this to extract database information through time-...

CVE-2023-24684

HIGH CVSS 7.2 Feb 9, 2023

ChurchCRM versions 4.5.3 and below contain a SQL injection vulnerability in the GetText.php file via the EID parameter. This allows attackers to execute arbitrary SQL commands on the database. All Chu...

CVE-2022-31325

HIGH CVSS 7.2 Jun 8, 2022

This SQL injection vulnerability in ChurchCRM 4.4.5 allows attackers to execute arbitrary SQL commands via the PersonID parameter in WhyCameEditor.php. This affects all ChurchCRM 4.4.5 installations w...

CVE-2021-41965

HIGH CVSS 8.8 May 15, 2022

This SQL injection vulnerability in ChurchCRM allows authenticated attackers to execute arbitrary SQL commands through unsanitized input fields (EN_tyid, theID, EID) during edit operations. It affects...

CVE-2026-24855

MEDIUM CVSS 5.4 Jan 30, 2026

ChurchCRM versions before 6.7.2 have a stored XSS vulnerability in the calendar event description field. Low-privilege users can inject malicious scripts that execute when other users view the event, ...

CVE-2025-68399

MEDIUM CVSS 5.4 Dec 17, 2025

ChurchCRM versions before 6.5.4 contain a stored cross-site scripting (XSS) vulnerability in the GroupEditor.php page. Authenticated users with group management permissions can inject malicious JavaSc...

CVE-2025-68401

MEDIUM CVSS 4.8 Dec 17, 2025

ChurchCRM versions before 6.0.0 have a stored cross-site scripting (XSS) vulnerability where user-supplied HTML/JavaScript isn't properly sanitized. Attackers can inject malicious scripts that execute...

CVE-2025-68275

MEDIUM CVSS 4.8 Dec 17, 2025

ChurchCRM versions before 6.5.3 have a stored cross-site scripting vulnerability on three people management pages. This allows attackers to inject malicious scripts that execute when users view those ...

CVE-2025-67875

MEDIUM CVSS 5.4 Dec 17, 2025

ChurchCRM versions before 6.5.3 contain a privilege escalation vulnerability where authenticated users with 'Edit Records' and 'Manage Properties and Classifications' permissions can inject persistent...

CVE-2025-67876

MEDIUM CVSS 5.4 Dec 17, 2025

A stored cross-site scripting (XSS) vulnerability in ChurchCRM allows low-privilege users with 'Manage Groups' permission to inject persistent JavaScript into group role names. This malicious code exe...

CVE-2025-67874

MEDIUM CVSS 6.5 Dec 16, 2025

ChurchCRM versions before 6.5.0 echo plaintext passwords back in HTTP responses, allowing attackers to steal user credentials. This affects all ChurchCRM installations running vulnerable versions. The...

CVE-2025-11939

MEDIUM CVSS 4.7 Oct 19, 2025

This vulnerability in ChurchCRM allows attackers to perform path traversal attacks via the restoreFile parameter in the backup restore functionality. Remote attackers can potentially access or manipul...

CVE-2025-11938

MEDIUM CVSS 5.6 Oct 19, 2025

A deserialization vulnerability in ChurchCRM's setup.php file allows remote attackers to potentially execute arbitrary code by manipulating DB_PASSWORD, ROOT_PATH, or URL parameters. This affects Chur...

CVE-2025-1024

MEDIUM CVSS 4.8 Feb 19, 2025

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.13.0 allows authenticated administrators to inject malicious JavaScript via the EID parameter in EditEventAttendees.php. This enable...