CVE-2025-68110

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
17/12/2025
Last modified:
18/12/2025

Description

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* 6.5.3 (excluding)