Stored Cross-Site Scripting in ChurchCRM Affects User Data Security
CVE-2025-68401

6.2MEDIUM

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
17 December 2025

What is CVE-2025-68401?

ChurchCRM, an open-source church management system, suffers from a stored Cross-Site Scripting (XSS) vulnerability allowing the execution of attacker-controlled JavaScript. The application prior to version 6.0.0 inadequately sanitizes and encodes user-supplied HTML/JS. If a user submits malicious content, any subsequent view by other users can lead to the execution of this script in their browsers. This exploitation can access sensitive information, such as web origin data, and may even perform privileged actions on behalf of the victim. Particularly concerning is the risk of session theft, especially when session cookies are not marked HttpOnly, as it opens avenues for account takeover. Version 6.0.0 addresses and mitigates this vulnerability.

Affected Version(s)

CRM < 6.0.0

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68401 : Stored Cross-Site Scripting in ChurchCRM Affects User Data Security