PT-2026-40458 · Churchcrm · Churchcrm

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-42288

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.3.2
Description A pre-authentication remote code execution issue exists in the setup wizard. The flaw allows for remote code execution via the unsanitized DB PASSWORD variable.
Recommendations Update to version 7.3.2.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-42288

Affected Products

Churchcrm