PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Web Vulnerabilities·Updated Nov 5, 2025

ChurchCRM - SQL Injection

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-1023
9.3
CVSScritical
Exploitable remotely over the internet · requires high privileges.

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
ChurchCRMby ChurchCRM
ChurchCRM 5.13.0 and prior
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ChurchCRM - SQL Injection CVE-2025-1023 Scanner | S4E