CVE 2 LOW

ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php_CVE-2025-68399

2 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P

Description

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue.

Basic Information

ID CVE-2025-68399
Source GitHub_M
Published Dec 17, 2025 at 21:40

Affected Product

Vendor ChurchCRM
Product CRM
Version < 6.5.4
Affected Versions ChurchCRM CRM < 6.5.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.