Churchcrm

Churchcrm

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.93%
  • Veröffentlicht 18.02.2025 10:15:10
  • Zuletzt bearbeitet 21.02.2025 15:21:54

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly con...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 18.02.2025 10:15:10
  • Zuletzt bearbeitet 21.02.2025 15:23:43

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript i...

  • EPSS 0.2%
  • Veröffentlicht 22.11.2024 17:15:10
  • Zuletzt bearbeitet 28.03.2025 16:39:27

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allo...

Exploit
  • EPSS 3.46%
  • Veröffentlicht 26.07.2024 18:15:03
  • Zuletzt bearbeitet 21.11.2024 09:27:25

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges ar...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 13.06.2024 14:15:12
  • Zuletzt bearbeitet 18.12.2025 18:29:51

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 21.02.2024 18:15:51
  • Zuletzt bearbeitet 17.03.2025 19:22:47

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

Exploit
  • EPSS 0.19%
  • Veröffentlicht 21.02.2024 18:15:51
  • Zuletzt bearbeitet 17.03.2025 19:22:56

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

Exploit
  • EPSS 8.92%
  • Veröffentlicht 21.02.2024 18:15:51
  • Zuletzt bearbeitet 17.03.2025 19:23:16

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 21.02.2024 18:15:51
  • Zuletzt bearbeitet 28.03.2025 17:15:26

A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 21.02.2024 18:15:51
  • Zuletzt bearbeitet 17.03.2025 19:22:39

ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.