George Dawoud
15 exploits
Active since Oct 2025
ChurchCRM < 6.7.2 - Authenticated SQL Injection via PaddleNumEditor.php PerID Parameter
CVSS 8.8
ChurchCRM < 6.7.2 - Stored Cross-Site Scripting in Church Calendar Event Description
CVSS 5.4
ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`
ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`
ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field
CVSS 5.4
ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function
CVSS 9.1
ChurchCRM: Username Enumeration via Differential Response in Public Login API
CVSS 5.3
ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion
CVSS 8.1
ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout
ChurchCRM <7.1.0 EditEventAttendees.php - Cross-Site Scripting
CVSS 6.1
ChurchCRM < 5.19.0 - Authentication Bypass in AuthMiddleware
CVSS 7.3
ChurchCRM < 6.2.0 - Time-Based Blind SQL Injection via 1FieldSec Parameter
CVSS 7.2
ChurchCRM < 6.5.0 - Authenticated SQL Injection via EN_tyid POST Parameter
CVSS 7.2
ChurchCRM < 6.5.0 - Plaintext Password Exposure in HTTP Responses
CVSS 6.5
ChurchCRM < 6.7.2 - Stored Cross-Site Scripting in Church Calendar Event Description
CVSS 5.4