ChurchCRM is a web-based membership and administrative platform for religious organizations, presenting a well-represented vulnerability footprint concentrated almost entirely within its core product. The exposure recurs consistently through web-application weakness classes including SQL injection, cross-site scripting, CSRF, improper authentication, and improper access control—defects endemic to PHP-based applications that handle sensitive member data and organizational records. A meaningful share of disclosures reach serious severity, and a moderate tendency exists toward public exploit availability, reflecting the accessibility of community software and the relatively straightforward exploitation vectors in server-side web applications. Defenders deploying this platform should prioritize timely patching and restrict administrative interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Churchcrm over time
Signals from CVEs in this vendor scope (110 CVEs).
110 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62521CRITICAL ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthent | Dec 17, 2025 | 9.8 | 46 | NO | YES |
CVE-2026-39339CRITICAL ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthM | Apr 7, 2026 | 9.1 | 43 | NO | YES |
CVE-2025-68109HIGH ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded fil | Dec 17, 2025 | 7.2 | 41 | NO | YES |
CVE-2025-1023CRITICAL A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the Ed | Feb 18, 2025 | 9.8 | 39 | NO | YES |
CVE-2024-39304HIGH ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of | Jul 26, 2024 | 8.8 | 37 | NO | YES |
CVE-2022-31325HIGH There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. | Jun 8, 2022 | 7.2 | 37 | NO | YES |
CVE-2026-39337CRITICAL ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthentic | Apr 7, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-68110HIGH ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. | Dec 17, 2025 | 8.8 | 32 | NO | NO |
CVE-2026-35573CRITICAL ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators | Apr 7, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-39328HIGH ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-ad | Apr 7, 2026 | 8.9 | 30 | NO | NO |
Signals from CVEs in this vendor scope (110 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Churchcrm.
Media articles that mention a CVE ID that affects a product developed by Churchcrm — matched by CVE ID, not by vendor name.