9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Description
ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the โManage Groupsโ permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover. As of time of publication, no known patched versions are available.
AI Analysis
Stored cross-site scripting (XSS) vulnerability in ChurchCRM group role names
Basic Information
ID
CVE-2025-67876
Source
GitHub_M
Published
Dec 17, 2025 at 21:18
Affected Product
Vendor
ChurchCRM
Product
CRM
Version
<= 6.4.0
Affected Versions
ChurchCRM CRM <= 6.4.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
ChurchCRM
Product
ChurchCRM
Version
6.4.0 and prior