Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39337

35
FAUCET Score

OVERVIEW CVE-2026-39337 is a critical pre-authentication remote code execution vulnerability affecting ChurchCRM versions prior to 7.1.0. The vulnerability exists in the setup wizard where the "$dbPassword" variable fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary PHP code during initial installation. This represents an incomplete remediation of a previously identified vulnerability (CVE-2025-62521). SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 (Critical) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The attack can be executed remotely over the network against any unpatched ChurchCRM installation during setup. The impact is severe, enabling complete compromise of the affected server including high-level confidentiality, integrity, and availability violations that could affect the entire network. EXPLOITATION STATUS The vulnerability is currently not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no indicators of active exploitation in the wild. The EPSS score of 0.0032 suggests lower real-world exploitation probability compared to other CVEs, and the vulnerability remains on an inactive hot list. However, organizations running ChurchCRM versions prior to 7.1.0 should prioritize immediate patching given the critical severity and exploitability during the setup phase.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.1.0CPE matchmatch criteria
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 32nd percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / ChurchCRM/CRM/security/advisories/GHSA-pm2v-ggh4-mp7p
Third Party Advisory