Church Admin
Vendor:
First CVE: May 28, 2015 · Active for 11 years
26
Total CVEs
More Total CVEs than 96% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Church Admin over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2015
11 years ago
Most Recent CVE
Jul 13, 2026
15 days ago
CVE Severity & Scoring
Church Admin26 CVEs
81%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (96.2%)
Unknown1 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High2 (7.7%)
Unknown1 (3.8%)
User Interaction
None14 (53.8%)
Unknown1 (3.8%)
Required11 (42.3%)
Privileges Required
Low11 (42.3%)
High3 (11.5%)
None11 (42.3%)
Unknown1 (3.8%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4127MEDIUM Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parame | May 28, 2015 | 4.3 | 32 | NO | YES |
CVE-2026-61983MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: | Jul 13, 2026 | 5.3 | 29 | NO | NO |
CVE-2025-26941CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin allows SQL Injection.This issue affects C | Mar 26, 2025 | 9.3 | 26 | NO | NO |
CVE-2024-37418CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6. | Jul 9, 2024 | 9.9 | 25 | NO | NO |
CVE-2024-31280HIGH Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5. | Apr 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-30244HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a | Mar 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-30782MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions. | Aug 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-57896MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: | Aug 22, 2025 | 5.3 | 19 | NO | NO |
CVE-2024-31281MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6. | May 17, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-30505MEDIUM Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18. | Mar 29, 2024 | 6.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 97th percentile
ExploitDB
1 CVE
3.8% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Church Admin
Top CWEs
Versions
No cataloged versions.