Churchcrm

Churchcrm

115 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 21:42:21
  • Zuletzt bearbeitet 18.12.2025 16:46:12

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` in ChurchCRM prior to version 6.5.3. Although the feature was removed from the UI, the file remains de...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 21:40:23
  • Zuletzt bearbeitet 18.12.2025 16:47:11

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can exe...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 17.12.2025 21:38:24
  • Zuletzt bearbeitet 18.12.2025 18:28:00

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 21:35:11
  • Zuletzt bearbeitet 18.12.2025 18:28:36

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within the "ReImport" functionality. An authenticated user with finance privileges can execute arbitrary SQ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 17.12.2025 21:33:36
  • Zuletzt bearbeitet 18.12.2025 18:29:30

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 17.12.2025 21:29:39
  • Zuletzt bearbeitet 18.12.2025 18:30:07

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequen...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 21:25:18
  • Zuletzt bearbeitet 18.12.2025 18:30:28

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, specifically in how the `PersonAddress` POST parameter is handled. Unlike other parameters in the sam...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 21:18:21
  • Zuletzt bearbeitet 18.12.2025 18:30:45

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the “Manage Groups” permission to inject persistent JavaScript ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.12.2025 21:16:16
  • Zuletzt bearbeitet 18.12.2025 18:31:12

ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticated user with specific mid-level permissions ("Edit Records" and "Manage Properties and Classification...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 17.12.2025 19:12:41
  • Zuletzt bearbeitet 18.12.2025 19:07:25

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in the Kiosk Manager feature suffers from broken access control, allowing any authenticated use...