CVE-2026-26059
- EPSS 0.03%
- Veröffentlicht 19.02.2026 18:45:53
- Zuletzt bearbeitet 20.02.2026 19:07:03
ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. V...
CVE-2026-24855
- EPSS 0.04%
- Veröffentlicht 30.01.2026 15:08:31
- Zuletzt bearbeitet 17.02.2026 14:32:44
ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description fiel...
CVE-2026-24854
- EPSS 0.03%
- Veröffentlicht 30.01.2026 15:05:12
- Zuletzt bearbeitet 17.02.2026 14:33:24
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL i...
CVE-2025-68275
- EPSS 0.05%
- Veröffentlicht 17.12.2025 21:53:22
- Zuletzt bearbeitet 18.12.2025 18:27:40
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnerability on the pages `View Active People`, `View Inactive people`, and `View All People`. Version 6.5.3 fixes the issue.
CVE-2025-68401
- EPSS 0.05%
- Veröffentlicht 17.12.2025 21:48:29
- Zuletzt bearbeitet 18.12.2025 16:44:00
ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/JS without sufficient sanitization/encoding. When other users later view this content, attacker-controlled JavaScript executes in ...
CVE-2025-68400
- EPSS 0.04%
- Veröffentlicht 17.12.2025 21:42:21
- Zuletzt bearbeitet 18.12.2025 16:46:12
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` in ChurchCRM prior to version 6.5.3. Although the feature was removed from the UI, the file remains de...
CVE-2025-68399
- EPSS 0.04%
- Veröffentlicht 17.12.2025 21:40:23
- Zuletzt bearbeitet 18.12.2025 16:47:11
ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can exe...
CVE-2025-68112
- EPSS 0.07%
- Veröffentlicht 17.12.2025 21:38:24
- Zuletzt bearbeitet 18.12.2025 18:28:00
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise...
CVE-2025-68111
- EPSS 0.04%
- Veröffentlicht 17.12.2025 21:35:11
- Zuletzt bearbeitet 18.12.2025 18:28:36
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within the "ReImport" functionality. An authenticated user with finance privileges can execute arbitrary SQ...
CVE-2025-68110
- EPSS 0.07%
- Veröffentlicht 17.12.2025 21:33:36
- Zuletzt bearbeitet 18.12.2025 18:29:30
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.