Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-26059 ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit g… Churchcrm 6.8.2+ Fix from $1,6002026-02-19 HIGH 8.8 CVE-2026-24854 ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to v… Churchcrm 6.7.2+ Fix from $1,9502026-01-30 MEDIUM 5.4 CVE-2026-24855 ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create… Churchcrm 6.7.2+ Fix from $1,6002026-01-30 HIGH 8.8 CVE-2025-68400 ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` i… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2025-68399 ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within t… Churchcrm 6.5.4+ Fix from $1,6002025-12-17 HIGH 8.8 CVE-2025-68112 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-68111 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists in the `eGive.php` file within… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-67877 ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-68110 ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the hos… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-68109 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2025-67875 ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to version 6.5.3. An authenticat… Churchcrm 6.5.3+ Fix from $1,6002025-12-17 MEDIUM 5.4 CVE-2025-67876 ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior … Churchcrm after 6.4.0 Fix from $1,6002025-12-17 HIGH 8.3 CVE-2025-66397 ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk func… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-66396 ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/UserEditor.php` file. … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-66395 ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. … Churchcrm 6.5.3+ Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2025-62521 ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM'… Churchcrm 5.21.0+ Fix from $2,3002025-12-17 HIGH 7.2 CVE-2025-67751 ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. Whe… Churchcrm 6.5.0+ Fix from $1,9502025-12-16 MEDIUM 6.5 CVE-2025-67874 ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in s… Churchcrm 6.5.0+ Fix from $1,6002025-12-16 HIGH 7.2 CVE-2025-66313 ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of th… Churchcrm after 6.2.0 Fix from $1,9502025-12-01 HIGH 7.2 CVE-2025-11939 A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php … Churchcrm after 5.18.0 Fix from $1,9502025-10-19 HIGH 8.1 CVE-2025-11938 A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipul… Churchcrm after 5.18.0 Fix from $1,9502025-10-19 CRITICAL 9.8 CVE-2025-11529 A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/Aut… Churchcrm 5.19.0+ Fix from $2,3002025-10-09 HIGH 8.8 CVE-2025-1132 A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. The para… Churchcrm after 5.13.0 Fix from $1,9502025-02-19 HIGH 7.2 CVE-2025-1133 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL… Churchcrm after 5.13.0 Fix from $1,9502025-02-19 HIGH 7.2 CVE-2025-1134 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-… Churchcrm after 5.13.0 Fix from $1,9502025-02-19 HIGH 7.2 CVE-2025-1135 A vulnerability exists in ChurchCRM 5.13.0. and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time… Churchcrm after 5.13.0 Fix from $1,9502025-02-19 CRITICAL 9.8 CVE-2025-1023 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL In… Churchcrm after 5.13.0 Fix from $2,3002025-02-18 MEDIUM 6.1 CVE-2025-0981 A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (… Churchcrm after 5.13.0 Fix from $1,6002025-02-18 CRITICAL 9.8 CVE-2024-53438 EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' paramet… Churchcrm Mitigation only Fix from $2,3002024-11-22 HIGH 8.8 CVE-2024-39304 ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due… Churchcrm 5.9.2+ Fix from $1,9502024-07-26