CVE-2026-39339
EUVD-2026-1983907.04.2026, 18:16
ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywhere in the request URL, leading to complete exposure of church member data and system information. This vulnerability is fixed in 7.1.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| churchcrm | churchcrm | 𝑥 < 7.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration