VYPR

Churchcrm

by Churchcrm

Source repositories

CVEs (125)

  • CVE-2026-24855MedJan 30, 2026
    risk 0.00cvss 5.4epss 0.00

    ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in…

  • CVE-2026-24854HigJan 30, 2026
    risk 0.00cvss 8.8epss 0.00

    ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID`…

  • CVE-2025-67874MedDec 16, 2025
    risk 0.00cvss 6.5epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify…

  • CVE-2025-67751HigDec 16, 2025
    risk 0.00cvss 7.2epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. When creating a new event and selecting an event type, the `EN_tyid` POST parameter is not sanitized. This allows an authenticated…

  • CVE-2025-66313HigDec 1, 2025
    risk 0.00cvss 7.2epss 0.00

    ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec parameter. Injecting SLEEP() causes deterministic server-side delays, proving the value is incorporated into a SQL…

Page 7 of 7