CVE-2026-40484 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: April 18, 2026
ChurchCRM - Remote Code Execution
Overview
ChurchCRM < 7.2.0 contains a remote code execution caused by lack of file extension filtering in database backup restore functionality and missing CSRF token validation, letting authenticated administrators execute arbitrary code via crafted backup archives and CSRF, exploit requires authenticated administrator.
Severity & Score
Impact
Authenticated administrators can execute arbitrary code remotely, leading to full server compromise.
Mitigation
Upgrade to version 7.2.0 or later.
References
Social Media Activity(4 posts)
š“ CVE-2026-40484 - Critical (9.1) ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using ... š https://www.thehackerwire.com/vulnerability/CVE-2026-40484/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postā ļø CRITICAL: ChurchCRM <7.2.0 vulnerable to RCE (CVE-2026-40484). Crafted backup restores allow webshell upload; CSRF flaw increases risk. Patch to 7.2.0+ now. Details: https://radar.offseq.com/threat/cve-2026-40484-cwe-269-improper-privilege-manageme-9bb4be14 #OffSeq #CVE202640484 #ChurchCRM #RCE
View original postš“ CVE-2026-40484 - Critical (9.1) ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using ... š https://www.thehackerwire.com/vulnerability/CVE-2026-40484/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postā ļø CRITICAL: ChurchCRM <7.2.0 vulnerable to RCE (CVE-2026-40484). Crafted backup restores allow webshell upload; CSRF flaw increases risk. Patch to 7.2.0+ now. Details: https://radar.offseq.com/threat/cve-2026-40484-cwe-269-improper-privilege-manageme-9bb4be14 #OffSeq #CVE202640484 #ChurchCRM #RCE
View original postRelated Resources
Details
- CVE ID
- CVE-2026-40484
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- unrestricted_file_upload
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H