Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ChurchCRM — Vulnerabilities & Security Advisories 76

Browse all 76 CVE security advisories affecting ChurchCRM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ChurchCRM is an open-source church management system designed to handle member data, donations, and group organization. Its extensive history of 68 recorded Common Vulnerabilities and Exposures highlights significant security deficiencies, primarily stemming from inadequate input validation and authentication controls. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often exacerbated by improper access control mechanisms that allow privilege escalation. These flaws frequently enable unauthenticated attackers to execute arbitrary code or extract sensitive organizational data. While the platform serves a niche administrative function, its security posture has been critically compromised by repeated failures to patch known issues. The accumulation of these defects suggests systemic neglect in code review and dependency management, posing substantial risks to institutions relying on the software for confidential member information and financial records.

Found 69 results / 76 Clear Filters
Top products by ChurchCRM: CRM ChurchCRM
CVE ID Title CVSS Severity Published
CVE-2026-39332 ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php — CRM CWE-79 8.7 High 2026-04-07
CVE-2026-39331 ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families — CRM CWE-639 8.1 High 2026-04-07
CVE-2026-39330 ChurchCRM has a Blind SQL injection in PropertyAssign.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39329 ChurchCRM has a Blind SQL injection in EventNames.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39328 ChurchCRM has Stored XSS in Social Profile Fields — CRM CWE-79 8.9 High 2026-04-07
CVE-2026-39327 ChurchCRM has a SQL injection in MemberRoleChange.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39326 ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39325 ChurchCRM has a Blind SQL injection in SettingsUser.php — CRM CWE-89 7.2 High 2026-04-07
CVE-2026-39318 ChurchCRM has a DDL SQL Injection in GroupPropsFormRowOps.php — CRM CWE-89 8.8 High 2026-04-07
CVE-2026-39335 ChurchCRM has Stored XSS via Unescaped data-* Attributes in Group/Family Controls — CRM CWE-79 6.1 Medium 2026-04-07
CVE-2026-35576 ChurchCRM has Stored Cross-Site Scripting (XSS) in Person Properties via PrintView.php — CRM CWE-79 8.7 High 2026-04-07
CVE-2026-35575 ChurchCRM has Stored XSS in Group Name — CRM CWE-79 8.0 High 2026-04-07
CVE-2026-35572 SSRF via Referer header in ChurchCRM allows server-side HTTP/HTTPS requests to arbitrary hosts — CRM CWE-918 7.1AI High AI 2026-04-07
CVE-2026-35573 ChurchCRM has a Path traversal leads to RCE — CRM CWE-22 9.1 Critical 2026-04-07
CVE-2026-35574 ChurchCRM has a Stored XSS in Person Profile - Add a Note — CRM CWE-79 7.3 High 2026-04-07
CVE-2026-35534 ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection — CRM CWE-79 7.6 High 2026-04-07
CVE-2026-32880 ChurchCRM is vulnerable to Stored XSS through JSON handling in SystemSettings.php — CRM CWE-79 6.4 Medium 2026-03-20
CVE-2026-26059 ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php — CRM CWE-79 5.4 - 2026-02-19
CVE-2026-24855 ChurchCRM has Stored Cross-Site Scripting (XSS) in Create Events in Church Calendar, Leading to Account Takeover — CRM CWE-79 5.4AI Medium AI 2026-01-30
CVE-2026-24854 Church CRM has SQL injection in PaddleNumEditor.php — CRM CWE-89 8.8 High 2026-01-30
CVE-2025-68275 ChurchCRM vulnerable to Stored XSS - Group name > Person Listing — CRM CWE-79 5.4AI Medium AI 2025-12-17
CVE-2025-68401 ChurchCRM has Stored Cross-Site Scripting (XSS) vulnerability that leads to session theft and account takeover — CRM CWE-79 7.6AI High AI 2025-12-17
CVE-2025-68400 ChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.php — CRM CWE-89 8.8AI High AI 2025-12-17
CVE-2025-68399 ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php — CRM CWE-79 5.4AI Medium AI 2025-12-17
CVE-2025-68112 ChurchCRM has SQL injection in EditEventAttendees.php — CRM CWE-89 9.6 Critical 2025-12-17
CVE-2025-68111 ChurchCRM has SQL Injection in eGive Import Feature — CRM CWE-89 7.2 High 2025-12-17
CVE-2025-68110 ChurchCRM discloses database information on error message — CRM CWE-200 10.0 Critical 2025-12-17
CVE-2025-68109 ChurchCRM vulnerable to RCE with database restore functionality — CRM CWE-78 9.1 Critical 2025-12-17
CVE-2025-67877 ChurchCRM SQL Injection Vulnerability — CRM CWE-89 8.8AI High AI 2025-12-17
CVE-2025-67876 ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking — CRM CWE-79 5.4AI Medium AI 2025-12-17

This page lists every published CVE security advisory associated with ChurchCRM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.