CVE-2025-68401

ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/JS without sufficient sanitization/encoding. When other users later view this content, attacker-controlled JavaScript executes in their browser (stored XSS). In affected contexts the script can access web origin data and perform privileged actions as the victim. Where session cookies are not marked HttpOnly, the script can read document.cookie, enabling session theft and account takeover. Version 6.0.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

18 Dec 2025, 16:44

Type Values Removed Values Added
First Time Churchcrm churchcrm
Churchcrm
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-phfw-p278-qq7v - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-phfw-p278-qq7v - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

18 Dec 2025, 15:16

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-phfw-p278-qq7v - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-phfw-p278-qq7v -

17 Dec 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-17 22:16

Updated : 2025-12-18 16:44


NVD link : CVE-2025-68401

Mitre link : CVE-2025-68401

CVE.ORG link : CVE-2025-68401


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')