Total CVEs

125,880

Critical Severity

2,277

High Severity

7,888

Last 7 Days

1,159
Quick preset (or use dates below)
Clear Filters
Showing 41 - 60 of 612 CVEs
CVE-2026-39338 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser'...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39337 CRITICAL - 10.0

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server com...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39336 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, Person editor defaults rendered into address fields, and external self-registration form defaults. This is primarily an admin-to-admin ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39335 MEDIUM - 6.1

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily an admin-to-admin stored XSS path when writable entity fields are abused. This vulnerability is fixed in 7.1.1.

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39334 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in ChurchCRM 7.0.5. Authenticated users without any specific privileges can inject arbitrary SQL statements through the type array parameter via the ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39333 HIGH - 8.7

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious UR...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39332 HIGH - 8.7

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocus...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39331 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} parameter in requests, regardless of whether they possess the required EditRecords privilege. /fami...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39330 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authenticated users with the role Manage Groups & Roles (ManageGroups) and Edit Records (isEditRecordsEnabled) can inject arbitrary SQL...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39329 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. Authenticated users with AddEvent privileges can inject SQL via the newEvtTypeCntLst parameter during event type creation. The vulnerable flow reaches ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39328 HIGH - 8.9

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39327 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in ChurchCRM 7.0.5. Authenticated users with the role Manage Groups & Roles (ManageGroups) can inject arbitrary SQL statements through the NewRole ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39326 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled can inject arbitrary SQL statements through the Name and Description parameters ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39325 HIGH - 7.2

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in ChurchCRM 7.0.5. Authenticated administrative users can inject arbitrary SQL statements through the type array parameter via the index and thus extract ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39323 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical SQL injection vulnerability exists in ChurchCRM's PropertyTypeEditor.php where the Name and Description POST parameters are sanitized only with strip_tags() before direct concatenation into SQL queries. This allows...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39319 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users can inject arbitrary SQL statements through ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39318 HIGH - 8.8

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRowOps.php`. A user has to be authenticated. For `ManageGroups` privileges have to ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39317 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in ChurchCRM's SettingsIndividual.php where user-controlled array keys from the type POST parameter are used directly in SQL queries without sanitization. This allows any authenticated use...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35576 HIGH - 8.7

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated user to inject arbitrary...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35575 HIGH - 8.0

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator v...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD