PT-2025-51922 · Churchcrm · Churchcrm

Lukasz-Rybak

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-67876

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions ChurchCRM versions 6.4.0 and prior
Description ChurchCRM is an open-source church management system affected by a stored cross-site scripting (XSS) issue. A user with the “Manage Groups” permission can inject persistent JavaScript into group role names. This malicious code is stored in the database and executed when any user views pages displaying that role, such as GroupView.php or PersonView.php. This can lead to full session hijacking and account takeover. The vulnerability impacts the display of group roles, potentially affecting any page that renders this information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67876
GHSA-J9GV-26C7-3QRH

Affected Products

Churchcrm