CVE-2026-42289 | ChurchCRM up to 7.3.1 HTML Page UserEditor.php privileges management (GHSA-3xq9-c86x-cwpp)
A vulnerability was found in ChurchCRM up to 7.3.1 and classified as critical. This issue affects some unknown processing of the file UserEditor.php of the component HTML Page. The manipulation results in improper privilege management.
This vulnerability is cataloged as CVE-2026-42289. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More