PT-2025-51940 · Churchcrm · Churchcrm

Janssensjelle

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-68275

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a stored cross-site scripting issue. This affects the View Active People, View Inactive people, and View All People pages. Privileged users can inject malicious scripts into people listing pages. These scripts execute when other administrators view the pages.
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68275
GHSA-3Q97-Q4HV-GXWR

Affected Products

Churchcrm