PT-2025-51928 · Churchcrm · Churchcrm

·

CVE-2025-68110

·

Published

2025-12-17

·

Updated

2026-05-21

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message, including the host, IP address, username, and password.
Recommendations Update ChurchCRM to version 6.5.3 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68110
GHSA-82MQ-XC2J-3QV2

Affected Products

Churchcrm