SQL injection in ChurchCRM - CVE-2025-67877
Published: April 9, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in /src/CartToFamily.php when handling the PersonAddress POST parameter in the Add to Family feature. A remote user can send a specially crafted POST request to disclose sensitive information.
Exploitation requires the Add Records permission.