Churchdb provides church-management software, with exposure centered on its ChurchInfo product and characterized by file-upload validation weaknesses. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Churchdb over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43258HIGH CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once | Nov 23, 2022 | 8.8 | 44 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Churchdb.
Media articles that mention a CVE ID that affects a product developed by Churchdb — matched by CVE ID, not by vendor name.