PT-2026-40464 · Churchcrm · Churchcrm

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2026-44548

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.3.2
Description Top-level cross-site GET navigation from an attacker-controlled page to the endpoints "FundRaiserDelete.php", "PropertyTypeDelete.php", or "NoteDelete.php" allows a logged-in user with the appropriate role to silently delete records. This includes the deletion of cascaded property and record-to-property assignments.
Recommendations Update to version 7.3.2.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-44548

Affected Products

Churchcrm