Church Admin Project maintains a narrowly scoped web-based church management application that serves administrative and organizational functions within religious institutions. The recurring vulnerability surface reflects typical web-application exposure: cross-site scripting, cross-site request forgery, missing authorization, server-side request forgery, and unrestricted file uploads—weakness classes that span input handling, access control, and file-processing boundaries and can expose congregation and administrative data when not patched. A meaningful share of the vendor's disclosures reach serious severity; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Church Admin Project over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4127MEDIUM Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parame | May 28, 2015 | 4.3 | 32 | NO | YES |
CVE-2026-61983MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: | Jul 13, 2026 | 5.3 | 29 | NO | NO |
CVE-2025-26941CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin allows SQL Injection.This issue affects C | Mar 26, 2025 | 9.3 | 26 | NO | NO |
CVE-2024-37418CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6. | Jul 9, 2024 | 9.9 | 25 | NO | NO |
CVE-2024-31280HIGH Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5. | Apr 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-30244HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a | Mar 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-30782MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions. | Aug 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-57896MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: | Aug 22, 2025 | 5.3 | 19 | NO | NO |
CVE-2024-31281MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6. | May 17, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-30505MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18. | Mar 29, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Church Admin Project.
Media articles that mention a CVE ID that affects a product developed by Church Admin Project — matched by CVE ID, not by vendor name.