Church Management System Project maintains a niche web-based application serving religious organizations, and its disclosures, though limited in volume, skew toward serious outcomes with a notable share reaching critical severity. The recurring vulnerability patterns center on SQL injection and unrestricted file upload in the core Church Management System product, reflecting common input-handling and file-validation gaps in web applications serving non-technical user bases. Defenders deploying this system should prioritize patching for these structural weaknesses, particularly in internet-exposed instances; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Church Management System Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41643CRITICAL Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. | Oct 29, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-41661CRITICAL Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploa | Jun 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-2680HIGH A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of th | Aug 5, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-45328HIGH Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php. | Nov 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-41406HIGH An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | Oct 12, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-38595HIGH Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. | Sep 15, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-38594HIGH Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. | Sep 15, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-38605HIGH Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php. | Sep 12, 2022 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Church Management System Project.
Media articles that mention a CVE ID that affects a product developed by Church Management System Project — matched by CVE ID, not by vendor name.