---
id: CVE-2025-67751
title: ChurchCRM is an open-source church management system
summary: >-
  ChurchCRM is an open-source church management system. Prior to version 6.5.0,
  a SQL injection vulnerability exists in the `EventEditor.php` file. When
  creating a new event and selecting an event type, the `EN_tyid` POST parameter
  is not …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: churchcrm
product: churchcrm
affected:
  - churchcrm < 6.5.0
patched:
  - churchcrm 6.5.0
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67751'
references:
  - url: >-
      https://github.com/ChurchCRM/CRM/commit/2d6cf7aed9af1b9b47e125d1a2266f8e2a88f3fd
    label: security-advisories@github.com
  - url: 'https://github.com/ChurchCRM/CRM/security/advisories/GHSA-wxcc-gvfv-56fg'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00404
epssPercentile: 0.32499
ingestedAt: '2026-10-07T20:46:46.945Z'
---

## Overview

ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in the `EventEditor.php` file. When creating a new event and selecting an event type, the `EN_tyid` POST parameter is not sanitized. This allows an authenticated user with event management permissions (`isAddEvent`) to execute arbitrary SQL queries. Version 6.5.0 fixes the issue.

## Affected

- `churchcrm < 6.5.0`

## Remediation

Upgrade past the affected range:

- `churchcrm 6.5.0`
