CVE-2025-67876

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the “Manage Groups” permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover. As of time of publication, no known patched versions are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

18 Dec 2025, 18:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-j9gv-26c7-3qrh - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-j9gv-26c7-3qrh - Exploit, Vendor Advisory
First Time Churchcrm churchcrm
Churchcrm

18 Dec 2025, 15:16

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-j9gv-26c7-3qrh - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-j9gv-26c7-3qrh -

17 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 22:16

Updated : 2025-12-18 18:30


NVD link : CVE-2025-67876

Mitre link : CVE-2025-67876

CVE.ORG link : CVE-2025-67876


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')