CVE-2026-40581

HIGH

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records ...

Affects 0 products across 2 vendors.

BCS4.87
CVSS 3.18.1
EPSS0.2%
Percentile10th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, no confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-352: Cross-Site Request Forgery (CSRF)

Web application does not verify that a request was intentionally sent by the authenticated user.

CWE-862: Missing Authorization

Software does not check whether an authenticated actor has permission for the requested operation.

Related Attack Patterns (CAPEC)
CAPEC-462 Cross-Domain Search Timing
via CWE-352
CAPEC-467 Cross Site Identification
via CWE-352
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-862
CAPEC-62 Cross Site Request Forgery
via CWE-352
CAPEC-111 JSON Hijacking (aka JavaScript Hijacking)
via CWE-352

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

ChurchCRM versions prior to 7.2.0 are vulnerable to unauthorized deletion of family records due to a lack of CSRF protection on the SelectDelete.php endpoint.

BSID: BS-2026-GLOBAL-265460-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-40581?
ChurchCRM versions prior to 7.2.0 are vulnerable to unauthorized deletion of family records due to a lack of CSRF protection on the SelectDelete.php endpoint.
What is the CVSS score for CVE-2026-40581?
CVE-2026-40581 has CVSS 8.1 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-40581 actively exploited?
No confirmed active exploitation of CVE-2026-40581 as of 2026-05-30.
How do I remediate CVE-2026-40581?
Priority: HIGH.
What systems are affected by CVE-2026-40581?
CVE-2026-40581 affects: Associated, Churchcrm.
Vulnerability Details
CVE IDCVE-2026-40581
BSIDBS-2026-GLOBAL-265460-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Published2026-04-18
Last Modified2026-04-20
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a malicious page that, when visited by an authenticated administrator, silently triggers deletion of targeted family records including associated notes, pledges, persons, and property data without any user interaction. This issue has been fixed in version 7.2.0.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can craft a malicious web page that, when visited by an authenticated administrator, can silently trigger the deletion of family records via a GET request to the SelectDelete.php endpoint without proper CSRF token validation.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Associated —
Churchcrm —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 98 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashc78aeb076426a9dfda64f6d0c51549a83032f3fe8f0a9d52b201e3096e3be308b5117ffae707b320809f239c8a38e5599f7a179a59b69541cfc9faad22224f55
Related CVEs affecting Associated
CVE-2024-2086 10.0 The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Ga... CVE-2025-40914 9.8 Perl CryptX before version 0.087 contains a dependency that may be susceptibl... CVE-2026-5229 9.8 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass i... CVE-2024-45337 9.1 Applications and libraries which misuse connection.serverAuthenticate (via ca... CVE-2025-10293 8.8 The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulner...
View all Associated CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →