Churchcrm · Churchcrm · CVE-2026-39940
**Name of the Vulnerable Software and Affected Versions**
ChurchCRM versions prior to 7.0.0
**Description**
An open-source church management system allows the creation of links that can redirect authenticated users to an arbitrary URL chosen by an attacker when the 'Cancel' button is clicked. This issue occurs in multiple locations across the application, such as in `DonatedItemEditor.php`, specifically where the `linkBack` variable is utilized.
**Recommendations**
Update to version 7.0.0.