CVE-2026-35567

8.8

ChurchCRM · ChurchCRM

ChurchCRM, an open-source church management platform, contains an unspecified vulnerability that requires further technical clarification to determine the precise impact and exploitation vector.

Executive summary

An unspecified security vulnerability in ChurchCRM poses a significant risk to organizational data integrity and system security, warranting immediate investigation and remediation.

Vulnerability

The vulnerability details for this entry are currently insufficient to identify the specific flaw or the required authentication level for exploitation.

Business impact

The CVSS score of 8.8 indicates a high-severity risk that could lead to significant unauthorized access or system compromise. If left unaddressed, this vulnerability may allow attackers to manipulate sensitive member data, disrupt administrative operations, or gain unauthorized control over the management system, leading to potential reputational and operational damage.

Remediation

Immediate Action: Organizations should monitor the official ChurchCRM repository and security advisories for the release of a patch or specific version guidance.

Proactive Monitoring: Security teams should review application and database access logs for unusual patterns, unauthorized login attempts, or anomalous administrative activity.

Compensating Controls: Deploy a Web Application Firewall with strict rule sets to inspect incoming traffic and block suspicious requests targeting the ChurchCRM web interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score, this vulnerability should be treated with urgency despite the current lack of specific technical details. Administrators must prioritize regular check-ins with official vendor channels and apply security updates as soon as they are made available to protect the integrity of the church management environment.

More ChurchCRM CVEs