CVE-2026-44548
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant role to silently delete records, including cascaded property and record-to-property assignments. This vulnerability is fixed in 7.3.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-352, CWE-650
- Published
- 2026-05-12
- Last modified
- 2026-05-13
Affected products
- ChurchCRM CRM
Weakness type
Related vulnerabilities
- CVE-2026-87449 — Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36...
- CVE-2026-9215 — A CSRF vulnerability exists in certain NETGEAR XR series devices
- CVE-2026-86724 — AVideo YPTWallet saveBalance.php Cross-Site Request Forgery
- CVE-2026-86719 — WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking
- CVE-2026-86718 — WWBN AVideo Cross-Site Request Forgery via deleteHistory.json.php
- CVE-2026-86135 — Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
- CVE-2026-33920 — Cross-site request forgery in the Guardian/CMC login before 26.3.0
- CVE-2026-76961 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)