Known Vulnerabilities for ChurchCRM by Na
Listed below are 10 of the newest known vulnerabilities associated with "ChurchCRM" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44548 json | ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-co... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-44547 json | ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The harde... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-42289 json | ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and perm... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42288 json | ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authe... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-40593 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders st... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40582 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validat... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40581 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (Select... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40485 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40484 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality e... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40483 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment ... | Not Provided | 2026-04-18 | 2026-04-20 |