Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Churchcrm

First CVE: May 15, 2022Active for: 4 yearsTotal CVEs: 110
55.8
VTI Score
TOP TARGET

ChurchCRM is a web-based membership and administrative platform for religious organizations, presenting a well-represented vulnerability footprint concentrated almost entirely within its core product. The exposure recurs consistently through web-application weakness classes including SQL injection, cross-site scripting, CSRF, improper authentication, and improper access control—defects endemic to PHP-based applications that handle sensitive member data and organizational records. A meaningful share of disclosures reach serious severity, and a moderate tendency exists toward public exploit availability, reflecting the accessibility of community software and the relatively straightforward exploitation vectors in server-side web applications. Defenders deploying this platform should prioritize timely patching and restrict administrative interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
110
Total CVEs
More Total CVEs than 99% of tracked vendors
22.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Churchcrm over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 15, 2022
4 years ago
Most Recent CVE
Apr 9, 2026
106 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (110 CVEs).

110 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-62521CRITICAL
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthent
Dec 17, 20259.846NOYES
CVE-2026-39339CRITICAL
ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthM
Apr 7, 20269.143NOYES
CVE-2025-68109HIGH
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded fil
Dec 17, 20257.241NOYES
CVE-2025-1023CRITICAL
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the Ed
Feb 18, 20259.839NOYES
CVE-2024-39304HIGH
ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of
Jul 26, 20248.837NOYES
CVE-2022-31325HIGH
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
Jun 8, 20227.237NOYES
CVE-2026-39337CRITICAL
ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthentic
Apr 7, 202610.035NONO
CVE-2025-68110HIGH
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password.
Dec 17, 20258.832NONO
CVE-2026-35573CRITICAL
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators
Apr 7, 20269.131NONO
CVE-2026-39328HIGH
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-ad
Apr 7, 20268.930NONO
View all 110 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products110 CVEs
35%
55%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.9%)
Network109 (99.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low106 (96.4%)
High4 (3.6%)
Unknown0 (0.0%)
User Interaction
None65 (59.1%)
Unknown0 (0.0%)
Required45 (40.9%)
Privileges Required
Low45 (40.9%)
High26 (23.6%)
None39 (35.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (110 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.8% of CVEs· 97th percentile
Nuclei
6 CVEs
5.5% of CVEs· 96th percentile
ExploitDB
3 CVEs
2.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Churchcrm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Churchcrm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Churchcrm's Products

View all 4 CNAs →

Top CWEs