Vulnerabilities in ChurchCRM

76 results
Vexday analysis

Com 72 CVEs catalogadas e 42 delas surgidas nos últimos 90 dias, o ChurchCRM apresenta um ritmo recente de descoberta de vulnerabilidades que merece atenção redobrada de equipes de segurança. Nenhuma CVE consta no catálogo KEV da CISA — taxa abaixo da média geral do catálogo —, o que indica ausência de exploração ativa confirmada, mas não reduz a preocupação com as 20 falhas de severidade crítica identificadas. O tipo de falha mais comum é CWE-89 (injeção de SQL), padrão que historicamente facilita comprometimento de dados e escalonamento de acesso, e a CVE mais perigosa atualmente é CVE-2025-62521, com escore EPSS de 0,0415. A presença de PoC pública em 2 CVEs eleva o risco de exploração oportunista, tornando a aplicação de correções uma prioridade operacional para ambientes que utilizam essa plataforma.

CVE-2026-39326HIGHChurchCRM has a Blind SQL injection in PropertyTypeEditor.phpEPSS 0.4%CVE-2026-39319HIGHChurchCRM has a Second Order SQLI via FundRaiserEditor.phpEPSS 0.4%CVE-2026-39329HIGHChurchCRM has a Blind SQL injection in EventNames.phpEPSS 0.4%CVE-2026-39334HIGHChurchCRM has a Blind SQL injection in SettingsIndividual.phpEPSS 0.4%CVE-2026-39327HIGHChurchCRM has a SQL injection in MemberRoleChange.phpEPSS 0.4%CVE-2026-39330HIGHChurchCRM has a Blind SQL injection in PropertyAssign.phpEPSS 0.4%CVE-2026-40480HIGHChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`EPSS 0.4%CVE-2025-68112CRITICALChurchCRM has SQL injection in EditEventAttendees.phpEPSS 0.4%CVE-2025-68110CRITICALChurchCRM discloses database information on error messageEPSS 0.4%CVE-2025-66396HIGHChurchCRM has SQL Injection in User Editor via `type` Parameter KeyEPSS 0.4%CVE-2026-39341HIGHSQL injection in ChurchCRM.0EPSS 0.4%CVE-2025-67751HIGHChurchCRM has SQL Injection in Event Editor via `EN_tyid` Parameter caused by an Incomplete FixEPSS 0.4%CVE-2025-66313MEDIUMChurchCRM vulnerable to a time-based blind SQL injection via the 1FieldSec parameterEPSS 0.4%CVE-2026-39344HIGHReflected XSS the login page through the 'username' parameterEPSS 0.4%CVE-2026-40485MEDIUMChurchCRM: Username Enumeration via Differential Response in Public Login APIEPSS 0.4%CVE-2026-39941MEDIUMChurchCRM has an XSS vulnerabilityEPSS 0.4%CVE-2026-39340HIGHChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer SubstitutionEPSS 0.4%CVE-2025-68400CRITICALChurchCRM vulnerable to time-based blind SQL Injection in ConfirmReportEmail.phpEPSS 0.4%CVE-2026-39335MEDIUMChurchCRM has Stored XSS via Unescaped data-* Attributes in Group/Family ControlsEPSS 0.4%CVE-2026-39331HIGHChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary FamiliesEPSS 0.4%