1. CRITICAL CVE-2026-44547: Authentication Bypass Vulnerability in ChurchCRM Allows Low-Privilege Attackers to Compromise Data (CVSS 9.6)
A critical improper authentication vulnerability has been identified in ChurchCRM, an open-source church management software platform. Tracked as CVE-2026-44547 and classified as CWE-287, the flaw carries a CVSS score of 9.6, placing it in the critical severity range. The vulnerability affects versions 7.2.0 through 7....