Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Churchcrm MEDIUM 5.4
CVE-2026-26059

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit g…

Fix: 6.8.2+
Fix from $1,600 2026-02-19
Churchcrm HIGH 8.8
CVE-2026-24854

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to v…

Fix: 6.7.2+
Fix from $1,950 2026-01-30
Churchcrm MEDIUM 5.4
CVE-2026-24855

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create…

Fix: 6.7.2+
Fix from $1,600 2026-01-30
Churchcrm HIGH 8.8
CVE-2025-68400

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` i…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm MEDIUM 5.4
CVE-2025-68399

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within t…

Fix: 6.5.4+
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-68112

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-68111

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-67877

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-68110

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the hos…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-68109

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm MEDIUM 5.4
CVE-2025-67875

ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticat…

Fix: 6.5.3+
Fix from $1,600 2025-12-17
Churchcrm MEDIUM 5.4
CVE-2025-67876

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior …

Fix: after 6.4.0
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.3
CVE-2025-66397

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk func…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-66396

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm HIGH 8.8
CVE-2025-66395

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. …

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Churchcrm CRITICAL 9.8
CVE-2025-62521

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'…

Fix: 5.21.0+
Fix from $2,300 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-67751

ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. Whe…

Fix: 6.5.0+
Fix from $1,950 2025-12-16
Churchcrm MEDIUM 6.5
CVE-2025-67874

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in s…

Fix: 6.5.0+
Fix from $1,600 2025-12-16
Churchcrm HIGH 7.2
CVE-2025-66313

ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of th…

Fix: after 6.2.0
Fix from $1,950 2025-12-01
Churchcrm HIGH 7.2
CVE-2025-11939

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php …

Fix: after 5.18.0
Fix from $1,950 2025-10-19
Churchcrm HIGH 8.1
CVE-2025-11938

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul…

Fix: after 5.18.0
Fix from $1,950 2025-10-19
Churchcrm CRITICAL 9.8
CVE-2025-11529

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut…

Fix: 5.19.0+
Fix from $2,300 2025-10-09
Churchcrm HIGH 8.8
CVE-2025-1132

A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The para…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1133

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1134

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm HIGH 7.2
CVE-2025-1135

A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time…

Fix: after 5.13.0
Fix from $1,950 2025-02-19
Churchcrm CRITICAL 9.8
CVE-2025-1023

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL In…

Fix: after 5.13.0
Fix from $2,300 2025-02-18
Churchcrm MEDIUM 6.1
CVE-2025-0981

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (…

Fix: after 5.13.0
Fix from $1,600 2025-02-18
Churchcrm CRITICAL 9.8
CVE-2024-53438

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' paramet…

Mitigation only
Fix from $2,300 2024-11-22
Churchcrm HIGH 8.8
CVE-2024-39304

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due…

Fix: 5.9.2+
Fix from $1,950 2024-07-26