Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

crm — Vulnerabilities & Security Advisories 87

All 87 CVE vulnerabilities found in crm, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CRM product category and its various software vendors. It aggregates security vulnerability data to provide a centralized view of the risk landscape for customer relationship management systems, focusing on weaknesses such as injection flaws, cross-site scripting, and insecure direct object references that commonly affect this domain. The collection covers publicly disclosed vulnerabilities from January 2020 through the current date, ensuring that both legacy issues and recent findings are included in the analysis. Visitors can use this resource to track vendor security advisories over time, understand the prevalence and impact of specific weakness classes within the CRM ecosystem, and look up a particular product’s historical vulnerability record to assess its long-term security posture. By examining trends and patterns across multiple vendors, users can identify systemic issues that may affect the entire industry segment rather than isolated incidents. The data is organized to facilitate comparative analysis, allowing security teams to prioritize remediation efforts based on severity and exposure. This approach supports informed decision-making for IT administrators and security analysts responsible for maintaining the integrity of CRM deployments. The page does not endorse any specific vendor but aims to provide neutral, factual information to enhance transparency and improve overall security hygiene in the customer relationship management sector.

Vendor: oroinc

CVE ID Title CVSS Severity Published
CVE-2026-58411 ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values CWE-79 - - 2026-07-13
CVE-2026-58410 ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records CWE-639 7.1 High 2026-07-13
CVE-2026-58409 ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload CWE-434 9.1 Critical 2026-07-13
CVE-2026-58408 ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII CWE-862 6.5 Medium 2026-07-13
CVE-2026-11456 Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection CWE-89 7.3 High 2026-06-07
CVE-2026-44548 ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php) CWE-352 8.1 High 2026-05-12
CVE-2026-44547 ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2 CWE-287 9.6 Critical 2026-05-12
CVE-2026-42288 ChurchCRM: Incomplete fix for CVE-2026-39337: Unauthenticated RCE in Setup Wizard via unsanitized DB_PASSWORD CWE-94 10.0 Critical 2026-05-12
CVE-2026-42289 ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation CWE-269 8.8 High 2026-05-12
CVE-2026-40593 ChurchCRM: Stored XSS in UserEditor.php via Login Name Field CWE-79 4.8 Medium 2026-04-18
CVE-2026-40581 ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion CWE-352 8.1 High 2026-04-17
CVE-2026-40485 ChurchCRM: Username Enumeration via Differential Response in Public Login API CWE-307 5.3 Medium 2026-04-17
CVE-2026-40484 ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function CWE-269 9.1 Critical 2026-04-17
CVE-2026-40483 ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field CWE-79 5.4 Medium 2026-04-17
CVE-2026-40582 ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout CWE-288 9.8AI Critical AI 2026-04-17
CVE-2026-40480 ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}` CWE-639 6.5AI Medium AI 2026-04-17
CVE-2026-40482 ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}` CWE-89 8.8AI High AI 2026-04-17
CVE-2026-39940 ChurchCRM has an Open Redirect via the ‘linkBack’ URL Parameter in DonatedItemEditor.php CWE-601 5.4 - 2026-04-13
CVE-2026-39941 ChurchCRM has an XSS vulnerability CWE-79 6.1AI Medium AI 2026-04-09
CVE-2026-39337 ChurchCRM Affected by Unauthenticated RCE in Install Wizard CWE-94 10.0 Critical 2026-04-07
CVE-2026-39319 ChurchCRM has a Second Order SQLI via FundRaiserEditor.php CWE-89 8.8 High 2026-04-07
CVE-2026-39344 Reflected XSS the login page through the 'username' parameter CWE-80 6.1AI Medium AI 2026-04-07
CVE-2026-39343 ChurchCRM has a SQL Injection in Event Type Editor (Admin) CWE-89 7.2 High 2026-04-07
CVE-2026-39342 ChurchCRM has a SQL injection searchwhat parameter via QueryView.php CWE-89 8.8AI High AI 2026-04-07
CVE-2026-39341 SQL injection in ChurchCRM.0 CWE-89 8.1 High 2026-04-07
CVE-2026-39340 ChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer Substitution CWE-89 8.1 High 2026-04-07
CVE-2026-39339 ChurchCRM has an API Authentication Bypass CWE-284 9.1 Critical 2026-04-07
CVE-2026-39338 ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-39336 ChurchCRM has Stored XSS from unescaped config values in HTML attributes CWE-79 6.1 Medium 2026-04-07
CVE-2026-39334 ChurchCRM has a Blind SQL injection in SettingsIndividual.php CWE-89 8.8 High 2026-04-07

All 87 known CVE vulnerabilities affecting crm with full Chinese analysis, references, and POCs where available.