Churchdesk is a niche vendor of church management and scheduling software, with disclosures centered on its ChurchRota product. The observed weakness class reflects a common risk in web applications that accept user-supplied files: unrestricted file upload mechanisms that lack proper type validation, which can lead to arbitrary code execution or data exposure if not carefully constrained. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Churchdesk over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3164HIGH ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a | Jan 26, 2021 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Churchdesk.
Media articles that mention a CVE ID that affects a product developed by Churchdesk — matched by CVE ID, not by vendor name.