#VU125679 SQL injection in ChurchCRM - CVE-2025-68400
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in ConfirmReportEmail.php when handling the familyId parameter in requests to the legacy /Reports/ConfirmReportEmail.php endpoint. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
The endpoint remains directly reachable by URL even though it was removed from the user interface.