SB2026040986 - Code Injection in ChurchCRM



SB2026040986 - Code Injection in ChurchCRM

Published: April 9, 2026

Security Bulletin ID SB2026040986
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Code Injection (CVE-ID: CVE-2025-62521)

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in setup/routes/setup.php when processing setup form input during the initial installation process. A remote attacker can submit specially crafted setup parameters to execute arbitrary code.

The issue affects fresh installations exposed through the unauthenticated setup wizard, and injected PHP code is written to Include/Config.php where it executes on subsequent page loads.


Remediation

Install update from vendor's website.