Churchcrm

Churchcrm

115 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Veröffentlicht 07.04.2026 18:16:45
  • Zuletzt bearbeitet 10.04.2026 20:59:05

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protecte...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 18:16:42
  • Zuletzt bearbeitet 10.04.2026 20:57:19

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:40:55
  • Zuletzt bearbeitet 10.04.2026 20:57:39

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, Person editor defaults rendered into address fields, and external self-registration f...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:38:45
  • Zuletzt bearbeitet 10.04.2026 20:57:47

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in ChurchCRM 7.0.5. Authenticated users without any specific privileges can inject arbitrary SQL st...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:38:02
  • Zuletzt bearbeitet 10.04.2026 20:57:56

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. ...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:37:23
  • Zuletzt bearbeitet 10.04.2026 20:58:07

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Bec...

  • EPSS 0.04%
  • Veröffentlicht 07.04.2026 17:36:41
  • Zuletzt bearbeitet 10.04.2026 20:58:16

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} parameter in requests, regardless of whether they poss...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:34:30
  • Zuletzt bearbeitet 10.04.2026 20:55:50

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authenticated users with the role Manage Groups & Roles (ManageGroups) and Edit Records (...

  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 17:33:30
  • Zuletzt bearbeitet 10.04.2026 20:58:26

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. Authenticated users with AddEvent privileges can inject SQL via the newEvtTypeCntLst parameter during...

  • EPSS 0.04%
  • Veröffentlicht 07.04.2026 17:32:41
  • Zuletzt bearbeitet 10.04.2026 20:56:24

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicio...