Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dawoudio

#50031of 56,333
5.3Total CVSS
Vulnerabilities · 1
PT-2026-32399
5.3
2026-04-13
Churchcrm · Churchcrm · CVE-2026-39940
**Name of the Vulnerable Software and Affected Versions** ChurchCRM versions prior to 7.0.0 **Description** An open-source church management system allows the creation of links that can redirect authenticated users to an arbitrary URL chosen by an attacker when the 'Cancel' button is clicked. This issue occurs in multiple locations across the application, such as in `DonatedItemEditor.php`, specifically where the `linkBack` variable is utilized. **Recommendations** Update to version 7.0.0.