CVE-2025-67877General(churchcrm / churchcrm)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch churchcrm churchcrm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, specifically in how the `PersonAddress` POST parameter is handled. Unlike other parameters in the same file which are correctly cast to integers using the `InputUtils` class, the `PersonAddress` parameter is missing the type definition. This allows an attacker to inject arbitrary SQL commands directly into the query. Version 6.5.3 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-10: 104-1004-20
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-101
General1
2026-04-201
PoC1
Full discourse2 posts
  • kilserv@kilserv
    General

    Já viram meu artigo da minha primeira CVE? Logo logo posto as outras duas também. #bolhasec #bolhadev https://kilserv.vercel.app/research/churchcrm-sqli-cve-2025-67877

    Post summary

    The user shares a link to an article about his first CVE (likely a SQL injection), but offers no PoC, exploit code, patch, or evidence of active exploitation.

    04125112.2K
    562 followersView on X
  • kilserv@kilserv
    PoC

    A vendor já aplicou os patches (CVE-2026-33288 e CVE-2026-33289). Pra quem curte code review e quer entender como a parada quebra por baixo dos panos, a PoC completinha no meu portfólio ou no medium: https://medium.com/@gui.mury.gm/from-code-analysis-to-cve-uncovering-sql-injection-in-churchcrm-cve-2025-67877-783c03863de9?postPublishedType=initial

    Post summary

    O texto anuncia que o fornecedor já aplicou patches para CVE-2026-33288 e CVE-2026-33289, e disponibiliza um PoC completo via Medium.

    00011231
    561 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more