CVE Tools

Churchcrm

102 CVEs tracked since 2023. Since Feb 2023, none of them reached CISA KEV.

Churchcrm CVEs per month

Feb 2023 to Apr 2026. Point at a month, or focus the strip and use the arrow keys.
Churchcrm CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0240
2023-03null or fewer
2023-0480
2023-0540
2023-06null or fewer
2023-07null or fewer
2023-08150
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-0280
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-0270
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12180
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04380

Products

The products that kept showing up in Churchcrm's monthly top three, with their CVEs summed over those months.

  1. Churchcrm938 months
  2. Crm562 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Churchcrm.

  1. CVE-2026-58411ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request parameter names and values—
  2. CVE-2026-58410ChurchCRM: Improper object-level authorization allows low-privileged users to read and modify other families’ records7.1
  3. CVE-2026-58409ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload9.1
  4. CVE-2026-58408ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privileged Users to Export All Members' PII6.5
  5. CVE-2026-44548ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)8.1
  6. CVE-2026-44547ChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.29.6
  7. CVE-2026-42288ChurchCRM: Incomplete fix for CVE-2026-39337: Unauthenticated RCE in Setup Wizard via unsanitized DB_PASSWORD10.0
  8. CVE-2026-42289ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation8.8
  9. CVE-2026-40593ChurchCRM: Stored XSS in UserEditor.php via Login Name Field4.8
  10. CVE-2026-40581ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion8.1
  11. CVE-2026-40485ChurchCRM: Username Enumeration via Differential Response in Public Login API5.3
  12. CVE-2026-40484ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function9.1
  13. CVE-2026-40483ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field5.4
  14. CVE-2026-40582ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockout—
  15. CVE-2026-40480ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`—

The record

Peak rank
#26 in Apr 2026
Busiest month shown
Apr 2026, 38 CVEs
Months with a KEV entry
0 since Feb 2023
Monthly snapshots
8 since 2023
Churchcrm's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store