CVE-2025-68399

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

18 Dec 2025, 16:47

Type Values Removed Values Added
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j - Exploit, Vendor Advisory
First Time Churchcrm churchcrm
Churchcrm

18 Dec 2025, 15:16

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-gfxf-w4cg-c54j -

17 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 22:16

Updated : 2025-12-18 16:47


NVD link : CVE-2025-68399

Mitre link : CVE-2025-68399

CVE.ORG link : CVE-2025-68399


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')