OVERVIEW CVE-2026-40484 affects ChurchCRM, an open-source church management system, in all versions prior to 7.2.0. The vulnerability exists in the database backup restore functionality, which extracts uploaded archive contents without proper file validation. An authenticated administrator can upload a malicious backup archive containing a PHP webshell in the Images/ directory, which is then copied to a web-accessible path and becomes executable via HTTP requests, enabling remote code execution. SEVERITY The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring high privileges (administrator authentication) but no user interaction. The impact is severe, affecting confidentiality, integrity, and availability across the affected system and potentially connected systems. Additionally, the restore endpoint lacks CSRF token validation, allowing unauthenticated attackers to trigger exploitation against compromised administrator sessions through cross-site request forgery attacks. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog and is not included on relevant threat intelligence hot lists. With an EPSS score of 0.000690000, the probability of exploitation remains extremely low relative to the CVE population. The vendor has addressed this issue in version 7.2.0, and administrators should prioritize upgrading to remediate the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ChurchCRM | CRM | < 7.2.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.