


Perceptive Security
SOC/SIEM Consultancy

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irr…
Published:
17 April 2026 at 22:00:00
Alert date:
18 April 2026 at 01:02:17
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
ChurchCRM versions prior to 7.2.0 contain a critical CSRF vulnerability in the family record deletion endpoint (SelectDelete.php). The vulnerability allows permanent, irreversible deletion of family records and associated data via GET requests without CSRF token validation. Attackers can craft malicious pages that silently trigger deletions when visited by authenticated administrators. The vulnerability affects sensitive data including family records, notes, pledges, persons, and property information. The issue has been patched in version 7.2.0.
Technical details
Mitigation steps:
Affected products:
ChurchCRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40581
https://github.com/ChurchCRM/CRM/commit/39361628613af7682b813f3e62a412559616d674
https://github.com/ChurchCRM/CRM/pull/8613
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-6qxv-xw9j-77pj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
