PT-2026-40463 · Churchcrm · Churchcrm
CVE-2026-44547
·
Published
2026-05-12
·
Updated
2026-05-13
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions 7.2.0 through 7.2.2
Description
An incomplete fix in the open-source church management system allows for exploitation because a hardening commit was removed from the
src/api/routes/public/public-user.php file by an unrelated pull request before the releases were tagged.Recommendations
Update ChurchCRM versions 7.2.0 through 7.2.2 to version 7.3.1.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm