🔐 CVE Alert

CVE-2026-39940

UNKNOWN 0.0

ChurchCRM has an Open Redirect via the ‘linkBack’ URL Parameter in DonatedItemEditor.php

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a link that, when visited by an authenticated user, would redirect them to any URL chosen by an attacker if they clicked 'Cancel' button on the page. For this write-up the DonatedItemEditor.php will be used as an example, however wherever all instances of 'linkBack' should be assessed. This vulnerability is fixed in 7.0.0.

CWE CWE-601
Vendor churchcrm
Product crm
Published Apr 13, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for churchcrm crm

Be the first to know when new unknown vulnerabilities affecting churchcrm crm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ChurchCRM / CRM
< 7.0.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ChurchCRM/CRM/security/advisories/GHSA-5g52-rvjf-6wwf github.com: https://github.com/ChurchCRM/CRM/security/advisories/GHSA-v3hj-33xf-qx47