Products: 1
Vulnerabilities: 128
Known Exploited: 0
15
Critical Level Threats
60
High Level Threats
43
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-44548
ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)
Last Modified: May 13, 2026
Published: May 12, 2026
CVE-2026-44547
ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2
Last Modified: May 13, 2026
Published: May 12, 2026
CVE-2026-42288
ChurchCRM: Incomplete fix for CVE-2026-39337: Unauthenticated RCE in Setup Wizard via unsanitized DB_PASSWORD
Last Modified: May 18, 2026
Published: May 12, 2026
CVE-2026-42289
ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation
Last Modified: May 14, 2026
Published: May 12, 2026
CVE-2026-40593
ChurchCRM: Stored XSS in UserEditor.php via Login Name Field
Last Modified: Apr 20, 2026
Published: Apr 18, 2026
Items Per Page
