Vulnerability index

Browse CVEs

101 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Churchcrm MEDIUM 6.1
CVE-2026-39941

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and ED…

Fix: 7.1.0+
Fix from $1,600 2026-04-09
Churchcrm HIGH 8.8
CVE-2026-39342

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39340

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the adm…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39341

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper in…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.2
CVE-2026-39343

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is o…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm CRITICAL 10.0
CVE-2026-39337

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's …

Fix: 7.1.0+
Fix from $2,300 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-39339

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (…

Fix: 7.1.0+
Fix from $2,300 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39334

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.ph…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39335

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. Th…

Fix: after 7.1.1
Fix from $1,600 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39336

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields s…

Fix: 7.1.0+
Fix from $1,600 2026-04-07
Churchcrm MEDIUM 6.1
CVE-2026-39338

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search param…

Fix: after 7.0.5
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.9
CVE-2026-39328

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profil…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39329

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39330

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-39332

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-39333

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and Date…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.1
CVE-2026-39331

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper a…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39326

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.ph…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39327

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php …

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.2
CVE-2026-39325

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in C…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39318

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRo…

Fix: after 7.0.5
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.8
CVE-2026-39319

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaise…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-35576

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within th…

Fix: 7.0.0+
Fix from $1,950 2026-04-07
Churchcrm HIGH 8.0
CVE-2026-35575

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s g…

Fix: 6.5.3+
Fix from $1,950 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo…

Fix: 6.5.3+
Fix from $2,300 2026-04-07
Churchcrm MEDIUM 6.0
CVE-2026-35572

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (S…

Fix: 6.5.3+
Fix from $1,600 2026-04-07
Churchcrm HIGH 8.7
CVE-2026-35574

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor al…

Fix: 6.5.3+
Fix from $1,950 2026-04-07
Churchcrm HIGH 7.6
CVE-2026-35534

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to inc…

Fix: 7.1.0+
Fix from $1,950 2026-04-07
Churchcrm MEDIUM 6.4
CVE-2026-32880

ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaSc…

Fix: 7.0.2+
Fix from $1,600 2026-03-20