CVE-2025-66313
- EPSS 0.04%
- Veröffentlicht 01.12.2025 22:13:20
- Zuletzt bearbeitet 03.12.2025 17:58:24
ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value i...
CVE-2025-11939
- EPSS 0.28%
- Veröffentlicht 19.10.2025 08:02:05
- Zuletzt bearbeitet 24.02.2026 08:16:18
A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. Executing a manipulation of the argument restoreFile can lea...
CVE-2025-11938
- EPSS 0.1%
- Veröffentlicht 19.10.2025 07:32:05
- Zuletzt bearbeitet 24.02.2026 08:16:18
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiat...
CVE-2025-11529
- EPSS 0.25%
- Veröffentlicht 09.10.2025 03:02:11
- Zuletzt bearbeitet 24.02.2026 07:16:37
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. Th...
CVE-2025-3954
- EPSS 0.64%
- Veröffentlicht 26.04.2025 21:31:03
- Zuletzt bearbeitet 29.05.2025 15:48:06
A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer Handler. The manipulation leads to server-side request forgery. The attack may be ...
CVE-2025-1133
- EPSS 0.16%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:26:57
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly conca...
CVE-2025-1024
- EPSS 0.15%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:50:07
A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects ...
CVE-2025-1132
- EPSS 0.12%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:48:03
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to injec...
CVE-2025-1134
- EPSS 0.29%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:21:18
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser...
CVE-2025-1135
- EPSS 0.29%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:18:49
A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the BatchWinnerEntry functionality. The CurrentFundraiser...