CVE-2025-1024
- EPSS 0.17%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:50:07
A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects ...
CVE-2025-1132
- EPSS 0.12%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:48:03
A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The parameter is directly inserted into an SQL query without proper sanitization, allowing attackers to injec...
CVE-2025-1133
- EPSS 0.18%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:26:57
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly conca...
CVE-2025-1134
- EPSS 0.15%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:21:18
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser...
CVE-2025-1135
- EPSS 0.15%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 25.02.2025 21:18:49
A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the BatchWinnerEntry functionality. The CurrentFundraiser...
CVE-2025-0981
- EPSS 0.13%
- Veröffentlicht 18.02.2025 10:15:10
- Zuletzt bearbeitet 21.02.2025 15:23:43
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript i...
CVE-2025-1023
- EPSS 2.62%
- Veröffentlicht 18.02.2025 10:15:10
- Zuletzt bearbeitet 21.02.2025 15:21:54
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly con...
CVE-2024-53438
- EPSS 0.2%
- Veröffentlicht 22.11.2024 17:15:10
- Zuletzt bearbeitet 28.03.2025 16:39:27
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allo...
CVE-2024-39304
- EPSS 3.46%
- Veröffentlicht 26.07.2024 18:15:03
- Zuletzt bearbeitet 21.11.2024 09:27:25
ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges ar...
CVE-2024-36647
- EPSS 0.78%
- Veröffentlicht 13.06.2024 14:15:12
- Zuletzt bearbeitet 18.12.2025 18:29:51
A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.