CVE-2026-44548CWE-352CWE-650
ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)
High · published May 12, 2026
What it is
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant role to silently delete records, including cascaded property and record-to-property assignments. This vulnerability is fixed in 7.3.2.
The record
Technical detail
- CVSS v3.1
- 8.1 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00120 · 2.0th percentile
- Weaknesses
- CWE-352 · Cross-Site Request Forgery (CSRF); CWE-650 · Trusting HTTP Permission Methods on the Server Side
- Published
- 2026-05-12T22:33Z
EPSS history
Timeline