← Back to browse · API

CVE-2026-42288

Severity
CRITICAL
CVSS
10.0
EPSS
0.00576
Risk score
40.2
CISA KEV
No
PoC
No
Published
2026-05-12
Modified
2026-05-18
First seen
2026-08-07
Aliases
EUVD-2026-29876
Products
ChurchCRM:crm < 7.3.2
Sources
euvd EUVD-2026-29876

Description

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully exploitable This vulnerability is fixed in 7.3.2.

References