Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shingleskat

#21997of 53,624
10.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-30891
5.3
2026-04-07
Churchcrm · Churchcrm · CVE-2026-35578
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.0.0 Description ChurchCRM is an open-source church management system. Prior to version 7.0.0, it was possible to create a link within the application that, when clicked by an authenticated user on the 'Cancel' button, would redirect them to a URL chosen by an attacker. This issue was observed in multiple areas of the application, including `DonatedItemEditor.php`, where all instances of 'linkBack' should be assessed. Recommendations Update to version 7.0.0 or later.
PT-2026-20912
5.4
2026-02-19
Churchcrm · Churchcrm · CVE-2026-26059
**Name of the Vulnerable Software and Affected Versions** ChurchCRM versions prior to 6.8.2 **Description** ChurchCRM is an open-source church management system. An authenticated user with permission to edit groups could store a JavaScript payload that would execute when the group was viewed in the Group View. The `Group View` is the affected component. Version 6.8.2 resolves this issue. **Recommendations** Update to version 6.8.2 or later.