Security Flaw in ChurchCRM Open-Source Management System
CVE-2026-44547

9.6CRITICAL

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44547?

ChurchCRM, an open-source church management system, is impacted by a security flaw where the fix for a previously identified issue was not fully implemented across versions 7.2.0 to 7.2.2. A hardening commit intended to address the vulnerability was inadvertently removed from the codebase by an unrelated pull request prior to the tagging of version 7.2.x. As a result, all shipped releases within this range remain susceptible to the proof of concept (PoC) exploit that was shared with the advisory. The vulnerability is effectively mitigated in version 7.3.1.

Affected Version(s)

CRM >= 7.2.0, < 7.3.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.