ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
| Vendors & Products |
Churchcrm
Churchcrm churchcrm |
Wed, 17 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue. | |
| Title | ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-18T15:08:14.394Z
Reserved: 2025-12-16T21:59:48.534Z
Link: CVE-2025-68399
No data.
Status : Analyzed
Published: 2025-12-17T22:16:02.083
Modified: 2025-12-18T16:47:11.970
Link: CVE-2025-68399
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:55:37Z