โ† All reports

ChurchCRM versions prior to 7.2.0 have multiple security vulnerabilities that could allow unauthorized access and data exposure.

CybersecurityApr 18, 2026score 0.177 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in ChurchCRM, an open-source church management system, affecting versions prior to 7.2.0. These vulnerabilities include SQL injection, insecure API endpoints, and improper handling of user input, which could lead to security risks such as unauthorized access and data exposure.

Claims

ChurchCRM versions prior to 7.2.0 have multiple security vulnerabilities that could allow unauthorized access and data exposure.
Parent: CybersecurityEntity: ChurchCRMImpact: negativeDate: Apr 18, 2026Target: ChurchCRM's security practices
The API endpoints in ChurchCRM versions prior to 7.2.0 are vulnerable to authentication bypass and information leakage.
Parent: CybersecurityEntity: ChurchCRMSub-entity: API endpointsImpact: negativeDate: Apr 18, 2026Target: Security of ChurchCRM API endpoints
ChurchCRM versions prior to 7.2.0 improperly handle user input, leading to potential cross-site scripting (XSS) and data exposure.
Parent: CybersecurityEntity: ChurchCRMSub-entity: User input handlingImpact: negativeDate: Apr 18, 2026Target: Security of user input handling in ChurchCRM

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23593 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23593 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23589 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces ca... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23589 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23601 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account l... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23601 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23595 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permission... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23595 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23597 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using recursiveCopy... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23597 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23599 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent users and 401 for vali... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23599 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23621 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: crm ๐Ÿข Vendor: ChurchCRM ๐Ÿ“… Updated: 2026-04-18 ๐Ÿ“ ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username co... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23621 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability