CVE-2025-68110
critical · 9.9ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.
9.9
CVSS
0.4%
EPSS (exploit prob.)
36th
EPSS percentile
2025-12-17
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-200CWE-209
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| churchcrm | churchcrm | < 6.5.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-68110