CVE-2026-39337Disclosure(churchcrm / churchcrm)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch churchcrm churchcrm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The "$dbPassword" variable is not sanitized. This vulnerability exists due to an incomplete fix for CVE-2025-62521. This vulnerability is fixed in 7.1.0.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-04-07); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-08: 2Mentions · 2026-04-18: 1Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-04-07: 1Active Exploitation · 2026-04-08: 1Patch / Workaround · 2026-04-07: 2Technical Details · 2026-04-07: 3Technical Details · 2026-04-18: 1Technical Details · 2026-05-12: 104-0704-0804-1805-12
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure3
2026-04-082
Active Exploitation1General1
2026-04-181
Disclosure1
2026-05-121
Disclosure1
Full discourse7 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-39337 | CVSS 10.0 🔴 CVE-2026-39933 | CVSS 10.0 🔴 CVE-2026-23696 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    A brief notification listing three high‑severity CVEs with their CVSS scores, offering no additional context or actionable information.

    0001080
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-39337: CRITICAL] Critical vulnerability in ChurchCRM's setup wizard pre-7.1.0 allows remote code execution. Unsanitized input in "$dbPassword" can compromise servers. Update to version 7.1.0 to fix.#cve,CVE-2026-39337,#cybersecurity https://cvefind.com/CVE-2026-39337

    Post summary

    The post reports a critical remote code execution vulnerability in ChurchCRM's pre‑7.1.0 setup wizard and recommends upgrading to version 7.1.0 to remediate it.

    00010196
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42288 ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerabi… https://www.cve.org/CVERecord?id=CVE-2026-42288

    Post summary

    The post announces CVE‑2026‑42288 affecting ChurchCRM prior to version 7.3.2, noting a pre‑authentication remote code execution flaw, and references the CVE record, but provides no PoC, exploit, or patch details.

    0000078
    57.5K followersView on X
  • Mr Elite@tradocaps_off
    Disclosure

    🔍 CVE-2026-39337 (CVSS 10.0 CRITICAL) — Check the details: https://securityelites.com/cve/CVE-2026-39337/?sc=10.0&sev=CRITICAL

    Post summary

    A new CVE‑2026‑39337 with a CVSS 10.0 score (CRITICAL) is announced, but no exploit, PoC, or patch details are provided.

    0000057
    11.0K followersView on X
  • Threat@THREATCHAIN
    Active Exploitation

    🚨 CVE-2026-39337: Church Management Software Flaw Gives Attackers Complete Server Control Your security tools might have missed this one. CVE-2026-39337 is actively targeting networks right now — here's what you need to know before it hits yours. https://threatchain.io/cve-2026-39337-church-management-software-flaw-gives-attackers-complete-server-c-39435d2c

    Post summary

    The post highlights CVE‑2026‑39337 as being actively exploited to give attackers full server control in church management software, yet it offers no PoC, exploit code, patch, or technical details.

    0000038
    15 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39337 ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allo… https://www.cve.org/CVERecord?id=CVE-2026-39337

    Post summary

    A discovery of a critical pre‑authentication remote code execution flaw in ChurchCRM before version 7.1.0 is announced, with no PoC, exploit tool, or patch details provided in the snippet.

    0000078
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39337: ChurchCRM Affected by Unauthenti... Unsanitized $dbPassword in setup wizard = instant shell access during fresh installs - incomplete CVE-2025-62521 patch ... https://zerodaysignal.com/vulnerability/CVE-2026-39337 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑39337 in ChurchCRM, reveals that an unsanitized database password during setup grants immediate shell access, and references a link for further details while noting an incomplete patch for a related CVE.

    00000219
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more