CVE-2025-67751High· 7.2▾ TwilightChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. When creating a new event and selecting an event type, the `EN_tyid` POST parameter is not …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the EventEditor.php file. When creating a new event and selecting an event type, the EN_tyid POST parameter is not sanitized. This allows an authenticated user with event management permissions (isAddEvent) to execute arbitrary SQL queries. Version 6.5.0 fixes the issue.
churchcrm < 6.5.0Upgrade past the affected range:
churchcrm 6.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67874Medium· 6.5ChurchCRM is an open-source church management system
CVE-2025-68109Critical· 9.1ChurchCRM is an open-source church management system
CVE-2025-67875Medium· 5.4ChurchCRM is an open-source church management system
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-11629Medium· 6.3A vulnerability has been found in RainyGao DocSys up to 2.02.36