CVE-2026-44547
ChurchCRM allows attackers to take control of your system
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A previous fix for ChurchCRM was incomplete and unintentionally removed, leaving versions 7.2.0-7.2.2 vulnerable to exploitation. This issue allows unauthorized access to sensitive data and system functions.