Churchcrm

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 128
    Known Exploited: 0
    15
    Critical Level Threats
    60
    High Level Threats
    43
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-44548

    ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2026-44547

    ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2026-42288

    ChurchCRM: Incomplete fix for CVE-2026-39337: Unauthenticated RCE in Setup Wizard via unsanitized DB_PASSWORD

    Last Modified: May 18, 2026
    Published: May 12, 2026

    CVE-2026-42289

    ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation

    Last Modified: May 14, 2026
    Published: May 12, 2026

    CVE-2026-40593

    ChurchCRM: Stored XSS in UserEditor.php via Login Name Field

    Last Modified: Apr 20, 2026
    Published: Apr 18, 2026
    Items Per Page
    Churchcrm Vulnerabilities & Security CVEs | CVE-DB