CVE 9.3 CRITICAL

ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking_CVE-2025-67876

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

Description

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the โ€œManage Groupsโ€ permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover. As of time of publication, no known patched versions are available.

AI Analysis

Stored cross-site scripting (XSS) vulnerability in ChurchCRM group role names

Basic Information

ID CVE-2025-67876
Source GitHub_M
Published Dec 17, 2025 at 21:18

Affected Product

Vendor ChurchCRM
Product CRM
Version <= 6.4.0
Affected Versions ChurchCRM CRM <= 6.4.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor ChurchCRM
Product ChurchCRM
Version 6.4.0 and prior

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.