Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-68112
CriticalVulnerability Description
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows authenticated users to execute arbitrary SQL commands, leading to complete database compromise, administrative credential theft, and potential system takeover. The vulnerability enables attackers to extract sensitive member data, authentication credentials, and financial information from the church management system. Version 6.5.3 contains a patch for the issue.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Known Affected Software
163 configuration(s) from 1 vendor(s)
cpe:2.3:a:churchcrm:churchcrm:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.12.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.5.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.9.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.13:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.15:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.9:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.4.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.6:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.14.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.10:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.7.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.13.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.8.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.18.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.16.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.9.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.5.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.2.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.10:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.9.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.9.0:-:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.10.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.10.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.17.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.8:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.10.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.5.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.7:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.0:-:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.7.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.11.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.5.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.11:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.14:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.9.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.12:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.19.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.9.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.2.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.4.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.2.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.15.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.4.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:2.8.11:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:churchcrm:churchcrm:5.2.0:*:*:*:*:*:*:*
Severity Details
Key Information
- Published Date
- December 17, 2025
