CVE-2025-68112

CRITICAL

ChurchCRM < 6.5.3 - Authenticated SQL Injection via Event Attendee Editor

Title source: llm
STIX 2.1

Description

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise, administrative credential theft, and potential system takeover. The vulnerability enables attackers to extract sensitive member data, authentication credentials, and financial information from the church management system. Version 6.5.3 contains a patch for the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 9.6
EPSS 0.0037
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
churchcrm/churchcrm < 6.5.3
Published Dec 17, 2025
Tracked Since Feb 18, 2026