Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ChurchCRM — Vulnerabilities & Security Advisories 76

Browse all 76 CVE security advisories affecting ChurchCRM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ChurchCRM is an open-source church management system designed to handle member data, donations, and group organization. Its extensive history of 68 recorded Common Vulnerabilities and Exposures highlights significant security deficiencies, primarily stemming from inadequate input validation and authentication controls. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often exacerbated by improper access control mechanisms that allow privilege escalation. These flaws frequently enable unauthenticated attackers to execute arbitrary code or extract sensitive organizational data. While the platform serves a niche administrative function, its security posture has been critically compromised by repeated failures to patch known issues. The accumulation of these defects suggests systemic neglect in code review and dependency management, posing substantial risks to institutions relying on the software for confidential member information and financial records.

Top products by ChurchCRM: CRM ChurchCRM
CVE ID Title CVSS Severity Published
CVE-2026-58411 ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values — CRM CWE-79 - - 2026-07-13
CVE-2026-58410 ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records — CRM CWE-639 7.1 High 2026-07-13
CVE-2026-58409 ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload — CRM CWE-434 9.1 Critical 2026-07-13
CVE-2026-58408 ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII — CRM CWE-862 6.5 Medium 2026-07-13
CVE-2026-44548 ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php) — CRM CWE-352 8.1 High 2026-05-12
CVE-2026-44547 ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2 — CRM CWE-287 9.6 Critical 2026-05-12
CVE-2026-42288 ChurchCRM: Incomplete fix for CVE-2026-39337: Unauthenticated RCE in Setup Wizard via unsanitized DB_PASSWORD — CRM CWE-94 10.0 Critical 2026-05-12
CVE-2026-42289 ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation — CRM CWE-269 8.8 High 2026-05-12
CVE-2026-40593 ChurchCRM: Stored XSS in UserEditor.php via Login Name Field — CRM CWE-79 4.8 Medium 2026-04-18
CVE-2026-40581 ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion — CRM CWE-352 8.1 High 2026-04-17
CVE-2026-40485 ChurchCRM: Username Enumeration via Differential Response in Public Login API — CRM CWE-307 5.3 Medium 2026-04-17
CVE-2026-40484 ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function — CRM CWE-269 9.1 Critical 2026-04-17
CVE-2026-40483 ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field — CRM CWE-79 5.4 Medium 2026-04-17
CVE-2026-40582 ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout — CRM CWE-288 9.8AI Critical AI 2026-04-17
CVE-2026-40480 ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}` — CRM CWE-639 6.5AI Medium AI 2026-04-17
CVE-2026-40482 ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}` — CRM CWE-89 8.8AI High AI 2026-04-17
CVE-2026-39940 ChurchCRM has an Open Redirect via the ‘linkBack’ URL Parameter in DonatedItemEditor.php — CRM CWE-601 5.4 - 2026-04-13
CVE-2026-39941 ChurchCRM has an XSS vulnerability — CRM CWE-79 6.1AI Medium AI 2026-04-09
CVE-2026-39337 ChurchCRM Affected by Unauthenticated RCE in Install Wizard — CRM CWE-94 10.0 Critical 2026-04-07
CVE-2026-39319 ChurchCRM has a Second Order SQLI via FundRaiserEditor.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39344 Reflected XSS the login page through the 'username' parameter — CRM CWE-80 6.1AI Medium AI 2026-04-07
CVE-2026-39343 ChurchCRM has a SQL Injection in Event Type Editor (Admin) — CRM CWE-89 7.2 High 2026-04-07
CVE-2026-39342 ChurchCRM has a SQL injection searchwhat parameter via QueryView.php — CRM CWE-89 8.8AI High AI 2026-04-07
CVE-2026-39341 SQL injection in ChurchCRM.0 — CRM CWE-89 8.1 High 2026-04-07
CVE-2026-39340 ChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer Substitution — CRM CWE-89 8.1 High 2026-04-07
CVE-2026-39339 ChurchCRM has an API Authentication Bypass — CRM CWE-284 9.1 Critical 2026-04-07
CVE-2026-39338 ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration — CRM CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-39336 ChurchCRM has Stored XSS from unescaped config values in HTML attributes — CRM CWE-79 6.1 Medium 2026-04-07
CVE-2026-39334 ChurchCRM has a Blind SQL injection in SettingsIndividual.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39333 ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php — CRM CWE-79 8.7 High 2026-04-07

This page lists every published CVE security advisory associated with ChurchCRM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.