---
id: CVE-2025-68109
title: ChurchCRM is an open-source church management system
summary: >-
  ChurchCRM is an open-source church management system. In versions prior to
  6.5.3, the Database Restore functionality does not validate the content or
  file extension of uploaded files. As a result, an attacker can upload a web
  shell file …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-434
  - CWE-494
  - CWE-552
  - CWE-915
vendor: churchcrm
product: churchcrm
affected:
  - churchcrm < 6.5.3
patched:
  - churchcrm 6.5.3
published: '2025-12-17'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T16:10:00.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68109'
references:
  - url: 'https://github.com/ChurchCRM/CRM/security/advisories/GHSA-pqm7-g8px-9r77'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.01547
epssPercentile: 0.74098
exploits:
  metasploit:
    - exploit/multi/http/churchcrm_db_restore_rce
  checkedAt: '2026-10-01T18:56:16.920Z'
exploitAvailable: true
ingestedAt: '2026-10-01T18:55:42.306Z'
---

## Overview

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file and subsequently upload a .htaccess file to enable direct access to it. Once accessed, the uploaded web shell allows remote code execution (RCE) on the server. Version 6.5.3 fixes the issue.

## Affected

- `churchcrm < 6.5.3`

## Remediation

Upgrade past the affected range:

- `churchcrm 6.5.3`
