Filtered by vendor Churchcrm
Subscribe
Total
110 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-11529 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | 7.5 HIGH | 7.3 HIGH |
| A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 3a1cffd2aea63d884025949cfbcfd274d06216a4. A patch should be applied to remediate this issue. | |||||
| CVE-2025-0981 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript in the description field, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information. | |||||
| CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 9.8 CRITICAL |
| EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |||||
| CVE-2024-39304 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 8.8 HIGH |
| ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue. | |||||
| CVE-2024-36647 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Family Name parameter under the Register a New Family page. | |||||
| CVE-2024-25898 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php. | |||||
| CVE-2024-25897 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 9.8 CRITICAL |
| ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. | |||||
| CVE-2024-25896 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 5.3 MEDIUM |
| ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter. | |||||
| CVE-2024-25895 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php | |||||
| CVE-2024-25894 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 9.8 CRITICAL |
| ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter. | |||||
| CVE-2024-25893 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 9.1 CRITICAL |
| ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. | |||||
| CVE-2024-25892 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 8.1 HIGH |
| ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter. | |||||
| CVE-2024-25891 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. | |||||
| CVE-2023-38773 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php. | |||||
| CVE-2023-38771 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryView.php. | |||||
| CVE-2023-38770 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php. | |||||
| CVE-2023-38769 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat parameters within the /QueryView.php. | |||||
| CVE-2023-38768 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the PropertyID parameter within the /QueryView.php. | |||||
| CVE-2023-38767 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value' and 'custom' parameters within the /QueryView.php. | |||||
| CVE-2023-38766 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component. | |||||
