VYPR

Churchcrm

by Churchcrm

Source repositories

CVEs (125)

  • CVE-2026-35576HigApr 7, 2026
    risk 0.50cvss 8.7epss 0.00

    ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated…

  • CVE-2022-31325HigJun 8, 2022
    risk 0.50cvss 7.2epss 0.05

    There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

  • CVE-2024-25891HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.01

    ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

  • CVE-2023-38773HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php.

  • CVE-2023-38771HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryView.php.

  • CVE-2023-38770HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.

  • CVE-2023-38769HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat parameters within the /QueryView.php.

  • CVE-2023-38768HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the PropertyID parameter within the /QueryView.php.

  • CVE-2023-38767HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value' and 'custom' parameters within the /QueryView.php.

  • CVE-2023-38765HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the membermonth parameter within the /QueryView.php.

  • CVE-2023-38764HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the birthmonth and percls parameters within the /QueryView.php.

  • CVE-2023-38762HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /QueryView.php.

  • CVE-2023-38760HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the role and gender parameters within the /QueryView.php component.

  • CVE-2023-26855HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

  • CVE-2025-68111HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.00

    ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within the "ReImport" functionality. An authenticated user with finance privileges can execute arbitrary SQL queries by manipulating the…

  • CVE-2025-66396HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. When an administrator saves a user's configuration settings, the keys of the `type` POST parameter array are not properly…

  • CVE-2025-1135HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the BatchWinnerEntry functionality. The CurrentFundraiser parameter is directly…

  • CVE-2025-1134HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser parameter is directly…

  • CVE-2025-1133HigFeb 19, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. The EID parameter is directly concatenated into an SQL query…

  • CVE-2023-24685HigFeb 9, 2023
    risk 0.47cvss 7.2epss 0.01

    ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

Page 3 of 7