Code Injection in ChurchCRM - CVE-2025-62521

 

Code Injection in ChurchCRM - CVE-2025-62521

Published: April 9, 2026


Vulnerability identifier: #VU125687
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62521
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in setup/routes/setup.php when processing setup form input during the initial installation process. A remote attacker can submit specially crafted setup parameters to execute arbitrary code.

The issue affects fresh installations exposed through the unauthenticated setup wizard, and injected PHP code is written to Include/Config.php where it executes on subsequent page loads.


Affected software

ChurchCRM

How to mitigate CVE-2025-62521

Install security update from vendor's website.

ChurchCRM - update to 5.21.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins