ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j | Exploit Vendor Advisory |
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j | Exploit Vendor Advisory |
Configurations
History
18 Dec 2025, 16:47
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j - Exploit, Vendor Advisory | |
| First Time |
Churchcrm churchcrm
Churchcrm |
18 Dec 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j - |
17 Dec 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 22:16
Updated : 2025-12-18 16:47
NVD link : CVE-2025-68399
Mitre link : CVE-2025-68399
CVE.ORG link : CVE-2025-68399
JSON object : View
Products Affected
churchcrm
- churchcrm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
