- Description
- ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The "$dbPassword" variable is not sanitized. This vulnerability exists due to an incomplete fix for CVE-2025-62521. This vulnerability is fixed in 7.1.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- churchcrm
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-94
- Hype score
- Not currently trending
CVE-2026-39337 - ChurchCRM - Critical pre-authentication RCE in the ChurchCRM setup wizard. - Unauthenticated attackers can inject arbitrary PHP code during the initial installation flow. - Impact: complete server compromise if exploitation succeeds. - CNA-assigned CVSS v3.1:
@CVE2026COIN
19 Jun 2026
10 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-39337: ChurchCRM Affected by Unauthenti... Unsanitized $dbPassword in setup wizard = instant shell access during fresh installs - incomplete CVE-2025-62521 patch ... https://t.co/mFS5oCmg28 #netsec #vulnerability #CVE #sysadmin #zeroday
@0dayPublishing
7 Apr 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BF846F61-0C1E-49AB-B691-A01937A6C24D",
"versionEndExcluding": "7.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]