Remote Code Execution Flaw in Church Management System by ChurchCRM
CVE-2026-42288

10CRITICAL

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-42288?

ChurchCRM, an open-source church management system, contains a pre-authentication remote code execution vulnerability in its setup wizard due to unsanitized DB_PASSWORD. This flaw allows attackers to exploit the system and execute arbitrary code without prior authentication. The vulnerability is particularly concerning as it remains fully exploitable in versions prior to 7.3.2. A fix has been implemented in version 7.3.2, addressing this security issue. Users are recommended to upgrade to the latest version to mitigate potential risks.

Affected Version(s)

CRM < 7.3.2

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.