2

CVSS4.0

CVE-2025-68399 - ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to wโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:40 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:40 p.m.

9.6

CVSS3.1

CVE-2025-68112 - ChurchCRM has SQL injection in EditEventAttendees.php

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise, administrative credential theft, and potential โ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:38 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:38 p.m.

7.2

CVSS3.1

CVE-2025-68111 - ChurchCRM has SQL Injection in eGive Import Feature

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within the "ReImport" functionality. An authenticated user with finance privileges can execute arbitrary SQL queries by manipulating the `MissingEgive_FamIDโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:35 p.m.

10

CVSS3.1

CVE-2025-68110 - ChurchCRM discloses database information on error message

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.

๐Ÿ“… Published: Dec. 17, 2025, 9:33 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:33 p.m.

9.1

CVSS3.1

CVE-2025-68109 - ChurchCRM vulnerable to RCE with database restore functionality

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct acceโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:29 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:29 p.m.

7.4

CVSS4.0

CVE-2025-67877 - ChurchCRM SQL Injection Vulnerability

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, specifically in how the `PersonAddress` POST parameter is handled. Unlike other parameters in the same file which are correctly cast to integers usingโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:25 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:25 p.m.

9.3

CVSS4.0

CVE-2025-67876 - ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the โ€œManage Groupsโ€ permission to inject persistent JavaScript into group role names. The payload is saved in thโ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:18 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:18 p.m.

8.5

CVSS4.0

CVE-2025-67875 - ChurchCRM has stored XSS via Person Property Assignment Leading to Admin Session Hijacking

ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticated user with specific mid-level permissions ("Edit Records" and "Manage Properties and Classifications") can inject a persistent Cross-Site Scripting โ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:16 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:16 p.m.

4.8

CVSS3.1

CVE-2025-68114 - Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflโ€ฆ

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStreamโ€™s index negative or past the end, leading to a stack buffer underflow/overflow when the next write occurs. Commit 2c7797182a16โ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:14 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:14 p.m.

4.8

CVSS3.1

CVE-2025-67873 - Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow

Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_iter memcpy more than 24 bytes into cs_insn.bytes, causing a heap buffer overflow in the disassembly path. Commit cbef767โ€ฆ

๐Ÿ“… Published: Dec. 17, 2025, 9:12 p.m. ๐Ÿ”„ Last Modified: Dec. 17, 2025, 9:12 p.m.
Total resulsts: 322987
Page 8 of 32,299
ยซ previous page ยป next page
Filters