OVERVIEW CVE-2026-39337 is a critical pre-authentication remote code execution vulnerability affecting ChurchCRM versions prior to 7.1.0. The vulnerability exists in the setup wizard where the "$dbPassword" variable fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary PHP code during initial installation. This represents an incomplete remediation of a previously identified vulnerability (CVE-2025-62521). SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 (Critical) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack can be executed remotely over the network against any unpatched ChurchCRM installation during setup. The impact is severe, enabling complete compromise of the affected server including high-level confidentiality, integrity, and availability violations that could affect the entire network. EXPLOITATION STATUS The vulnerability is currently not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no indicators of active exploitation in the wild. The EPSS score of 0.0032 suggests lower real-world exploitation probability compared to other CVEs, and the vulnerability remains on an inactive hot list. However, organizations running ChurchCRM versions prior to 7.1.0 should prioritize immediate patching given the critical severity and exploitability during the setup phase.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.1.0CPE matchmatch criteria | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.