#VU125685 SQL injection in ChurchCRM - CVE-2025-68111
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary SQL queries.
The vulnerability exists due to SQL injection in the eGive ReImport functionality in src/eGive.php when processing the MissingEgive_FamID_* POST parameter. A remote privileged user can send a specially crafted POST request to execute arbitrary SQL queries.
Exploitation requires the eGive import flow to reach the re-import form for missing eGive IDs.