CVE-2025-67874Medium· 6.5▾ SunlitChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk o…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify the impact of other vulnerabilities (e.g., XSS, IDOR, session fixation), enabling attackers to harvest other users’ passwords. Version 6.5.0 fixes the issue.
churchcrm < 6.5.0Upgrade past the affected range:
churchcrm 6.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67751High· 7.2ChurchCRM is an open-source church management system
CVE-2025-68109Critical· 9.1ChurchCRM is an open-source church management system
CVE-2025-67875Medium· 5.4ChurchCRM is an open-source church management system
CVE-2025-40806Medium· 5.3A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1)
CVE-2018-25350Critical· 9.8userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint
CVE-2026-59785Medium· 5.1Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials