Churchcrm Churchcrm Vulnerabilities

3 advisories affecting Churchcrm Churchcrm

3

Total CVEs

3

Critical

0

High

CVE-2026-35573

Apr 7, 2026

Critical (9.1)

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary...

Read Advisory

CVE-2026-39337

Apr 7, 2026

Critical (10.0)

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to in...

Read Advisory

CVE-2026-39339

Apr 7, 2026

Critical (9.1)

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allow...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.