Technology · ChurchCRM
ChurchCRM vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 11 vulnerabilities in ChurchCRM: 0 in the last 7 days and 3 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58410, was published on 13 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 3
- Exploited in the wild
- 0
About ChurchCRM
ChurchCRM is an open-source church management system designed to manage member data, finances, and groups.
Latest ChurchCRM vulnerabilities
- CVE-2026-58410: ChurchCRM CRM authorization bypass in family-scoped endpointshighCVSS 7.1
- CVE-2026-58409: ChurchCRM unrestricted file upload in plugin installercriticalCVSS 9.1
- CVE-2026-58408: ChurchCRM broken access control in CSVCreateFile.php exportmediumCVSS 6.5
- CVE-2026-44548: ChurchCRM CSRF in legacy delete endpointshighCVSS 8.1
- CVE-2026-44547: ChurchCRM 2FA and account lockout bypass in public API logincriticalCVSS 9.6
- CVE-2026-42289: ChurchCRM CSRF in UserEditor.php leads to privilege escalationhighCVSS 8.8
- CVE-2026-42288: ChurchCRM remote code execution in setup wizardcriticalCVSS 10EPSS 0.3%
- CVE-2026-39344: ChurchCRM reflected XSS in login page username parameterhighCVSS 8.1EPSS 0.3%
- CVE-2026-39343: ChurchCRM SQL injection in EditEventTypes.phphighCVSS 7.2EPSS 0.3%
- CVE-2026-39342: ChurchCRM SQL injection in QueryView.php searchwhat parameterhighCVSS 8.8EPSS 0.3%
- CVE-2026-39341: ChurchCRM SQL injection in ConfirmReportEmail.phphighCVSS 8.1EPSS 0.3%
Most severe ChurchCRM vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42288: ChurchCRM remote code execution in setup wizardcriticalCVSS 10EPSS 0.3%
- CVE-2026-44547: ChurchCRM 2FA and account lockout bypass in public API logincriticalCVSS 9.6
- CVE-2026-58409: ChurchCRM unrestricted file upload in plugin installercriticalCVSS 9.1
- CVE-2026-39342: ChurchCRM SQL injection in QueryView.php searchwhat parameterhighCVSS 8.8EPSS 0.3%
- CVE-2026-42289: ChurchCRM CSRF in UserEditor.php leads to privilege escalationhighCVSS 8.8
- CVE-2026-39341: ChurchCRM SQL injection in ConfirmReportEmail.phphighCVSS 8.1EPSS 0.3%
- CVE-2026-39344: ChurchCRM reflected XSS in login page username parameterhighCVSS 8.1EPSS 0.3%
- CVE-2026-44548: ChurchCRM CSRF in legacy delete endpointshighCVSS 8.1
- CVE-2026-39343: ChurchCRM SQL injection in EditEventTypes.phphighCVSS 7.2EPSS 0.3%
- CVE-2026-58410: ChurchCRM CRM authorization bypass in family-scoped endpointshighCVSS 7.1
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 3 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/churchcrm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ChurchCRM vulnerabilities", https://junglewise.ai/threats/technologies/churchcrm, 26 September 2026.