Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Church Admin Project

First CVE: May 28, 2015Active for: 11 yearsTotal CVEs: 26
25.2
VTI Score
Low

Church Admin Project maintains a narrowly scoped web-based church management application that serves administrative and organizational functions within religious institutions. The recurring vulnerability surface reflects typical web-application exposure: cross-site scripting, cross-site request forgery, missing authorization, server-side request forgery, and unrestricted file uploads—weakness classes that span input handling, access control, and file-processing boundaries and can expose congregation and administrative data when not patched. A meaningful share of the vendor's disclosures reach serious severity; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Church Admin Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2015
11 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-4127MEDIUM
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parame
May 28, 20154.332NOYES
CVE-2026-61983MEDIUM
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin:
Jul 13, 20265.329NONO
CVE-2025-26941CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin allows SQL Injection.This issue affects C
Mar 26, 20259.326NONO
CVE-2024-37418CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6.
Jul 9, 20249.925NONO
CVE-2024-31280HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.
Apr 7, 20248.824NONO
CVE-2024-30244HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a
Mar 28, 20248.823NONO
CVE-2023-30782MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.
Aug 16, 20236.120NONO
CVE-2025-57896MEDIUM
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin:
Aug 22, 20255.319NONO
CVE-2024-31281MEDIUM
Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.
May 17, 20246.319NONO
CVE-2024-30505MEDIUM
Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18.
Mar 29, 20246.519NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
81%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (96.2%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High2 (7.7%)
Unknown1 (3.8%)
User Interaction
None14 (53.8%)
Unknown1 (3.8%)
Required11 (42.3%)
Privileges Required
Low11 (42.3%)
High3 (11.5%)
None11 (42.3%)
Unknown1 (3.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
1 CVE
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Church Admin Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Church Admin Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Church Admin Project's Products

View all 4 CNAs →

Top CWEs