CVE-2025-66396
- EPSS 0.04%
- Veröffentlicht 17.12.2025 19:10:49
- Zuletzt bearbeitet 18.12.2025 19:08:03
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. When an administrator saves a user's configuration settings, the keys of the `type` POST parameter ar...
CVE-2025-66395
- EPSS 0.04%
- Veröffentlicht 17.12.2025 19:04:44
- Zuletzt bearbeitet 18.12.2025 19:08:38
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. When filtering events by type, the `WhichType` POST parameter is not properly sanitized or type-caste...
CVE-2025-62521
- EPSS 57.69%
- Veröffentlicht 17.12.2025 19:03:20
- Zuletzt bearbeitet 18.12.2025 19:10:00
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial insta...
CVE-2025-67751
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:46:30
- Zuletzt bearbeitet 17.12.2025 14:15:14
ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. When creating a new event and selecting an event type, the `EN_tyid` POST parameter is not sanitized. Th...
CVE-2025-67874
- EPSS 0.04%
- Veröffentlicht 16.12.2025 00:44:43
- Zuletzt bearbeitet 17.12.2025 14:14:08
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential ...
CVE-2025-66313
- EPSS 0.06%
- Veröffentlicht 01.12.2025 22:13:20
- Zuletzt bearbeitet 03.12.2025 17:58:24
ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value i...
CVE-2025-11939
- EPSS 0.21%
- Veröffentlicht 19.10.2025 08:02:05
- Zuletzt bearbeitet 24.02.2026 08:16:18
A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. Executing a manipulation of the argument restoreFile can lea...
CVE-2025-11938
- EPSS 0.1%
- Veröffentlicht 19.10.2025 07:32:05
- Zuletzt bearbeitet 24.02.2026 08:16:18
A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiat...
CVE-2025-11529
- EPSS 0.11%
- Veröffentlicht 09.10.2025 03:02:11
- Zuletzt bearbeitet 24.02.2026 07:16:37
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. Th...
CVE-2025-3954
- EPSS 0.64%
- Veröffentlicht 26.04.2025 21:31:03
- Zuletzt bearbeitet 29.05.2025 15:48:06
A vulnerability, which was classified as problematic, has been found in ChurchCRM 5.16.0. Affected by this issue is some unknown functionality of the component Referer Handler. The manipulation leads to server-side request forgery. The attack may be ...