PT-2025-51940 · Churchcrm · Churchcrm

·

CVE-2025-68275

·

Published

2025-12-17

·

Updated

2025-12-20

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a stored cross-site scripting issue. This affects the View Active People, View Inactive people, and View All People pages. Privileged users can inject malicious scripts into people listing pages. These scripts execute when other administrators view the pages.
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68275
GHSA-3Q97-Q4HV-GXWR

Affected Products

Churchcrm