Mehrere Schwachstellen (CVE-2026-33824, CVE-2026-33827, CVE-2026-40621, CVE-2026-42062, CVE-2026-42288, CVE-2026-44547) in Churchcrm
⚠️ CVE-Referenzen:
CVE-2026-33824
CVE-2026-33827
CVE-2026-40621
CVE-2026-42062
CVE-2026-42288
CVE-2026-44547
Churchcrm - Crm - CRITICAL - CVE-2026-44547.
ChurchCRM, an open-source church management system, is impacted by a security flaw where the fix for a previously identified issue was not fully implemented across versions 7.2.0 to 7.2.2. A hardening commit intended to address the vulnerability was inadvertently removed from the codebase by an unrelated pull request prior to the tagging of version 7.2.x. As a result, all shipped releases within this range remain susceptible to the proof of concept (PoC) exploit that was shared with the advisory. The vulnerability is effectively mitigated in version 7.3.1.
Quelle: securityvulnerability.io