Back to Database
Status published
Critical
CVE-2025-68275
ChurchCRM vulnerable to Stored XSS - Group name > Person Listing
Vulnerability Description
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnerability on the pages `View Active People`, `View Inactive people`, and `View All People`. Version 6.5.3 fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68275
Credits & Attribution
No credits recorded in the NVD database.
More from ChurchCRM
View All →CVE-2025-68401
ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and account takeover
Medium
6.2
CVE-2025-68400
ChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.php
Critical
9.3
CVE-2025-68399
ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php
Low
2
CVE-2025-68112
ChurchCRM has SQL injection in EditEventAttendees.php
Critical
9.6
CVE-2025-68111
ChurchCRM has SQL Injection in eGive Import Feature
High
7.2
Affected Vendor
ChurchCRM
View all reports →Affected Software
CRM
Vulnerable Versions:
< 6.5.3
Timeline
Official Publish:
December 17th, 2025
Last Modified:
December 18th, 2025
Added to House:
July 22nd, 2026