← All CVEs

CVE-2025-68110

critical · 9.9

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.

9.9
CVSS
0.4%
EPSS (exploit prob.)
36th
EPSS percentile
2025-12-17
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-200CWE-209

Affected products

VendorProductAffected versions
churchcrmchurchcrm< 6.5.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-68110