---
id: CVE-2025-67874
title: ChurchCRM is an open-source church management system
summary: >-
  ChurchCRM is an open-source church management system. Prior to version 6.5.0,
  the application echoes back plaintext passwords submitted by users in
  subsequent HTTP responses. This information disclosure significantly increases
  the risk o…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-204
vendor: churchcrm
product: churchcrm
affected:
  - churchcrm < 6.5.0
patched:
  - churchcrm 6.5.0
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67874'
references:
  - url: >-
      https://github.com/ChurchCRM/CRM/commit/2d6cf7aed9af1b9b47e125d1a2266f8e2a88f3fd
    label: security-advisories@github.com
  - url: 'https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p98h-5xcj-5c6x'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00355
epssPercentile: 0.27086
ingestedAt: '2026-10-07T20:46:46.945Z'
---

## Overview

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This information disclosure significantly increases the risk of credential compromise and may amplify the impact of other vulnerabilities (e.g., XSS, IDOR, session fixation), enabling attackers to harvest other users’ passwords. Version 6.5.0 fixes the issue.

## Affected

- `churchcrm < 6.5.0`

## Remediation

Upgrade past the affected range:

- `churchcrm 6.5.0`
