VYPR

Churchcrm

by Churchcrm

Source repositories

CVEs (125)

  • CVE-2026-40482HigApr 18, 2026
    risk 0.39cvss epss 0.00

    ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.

  • CVE-2026-40480HigApr 18, 2026
    risk 0.39cvss epss 0.00

    ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces canEditPerson()…

  • CVE-2025-11938MedOct 19, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's…

  • CVE-2026-32880MedMar 20, 2026
    risk 0.35cvss 6.4epss 0.00

    ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaScript payload that can execute when any admin views the system settings. The JSON input is left unescaped/unsanitized in…

  • CVE-2026-26059MedFeb 19, 2026
    risk 0.35cvss 5.4epss 0.00

    ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue.

  • CVE-2025-68399MedDec 17, 2025
    risk 0.35cvss 5.4epss 0.00

    ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript.…

  • CVE-2025-67876MedDec 17, 2025
    risk 0.35cvss 5.4epss 0.00

    ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the “Manage Groups” permission to inject persistent JavaScript into group role names.…

  • CVE-2025-67875MedDec 17, 2025
    risk 0.35cvss 5.4epss 0.00

    ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticated user with specific mid-level permissions ("Edit Records" and "Manage Properties and Classifications") can inject a persistent…

  • CVE-2024-36647MedJun 13, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page.

  • CVE-2020-28849MedAug 11, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.

  • CVE-2023-38766MedAug 8, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component.

  • CVE-2023-31548MedMay 31, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2023-26842MedMay 31, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.

  • CVE-2023-26843MedApr 25, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

  • CVE-2023-25347MedApr 25, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

  • CVE-2023-27059MedMar 16, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field.

  • CVE-2023-24690MedFeb 9, 2023
    risk 0.35cvss 5.4epss 0.00

    ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.

  • CVE-2024-25896MedFeb 21, 2024
    risk 0.34cvss 5.3epss 0.00

    ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

  • CVE-2023-31699MedMay 17, 2023
    risk 0.34cvss 4.8epss 0.02

    ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.

  • CVE-2023-26840MedApr 25, 2023
    risk 0.34cvss 5.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator.

Page 5 of 7