
CVE-2026-35572 ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (SSRF) by supplying… https://www.cve.org/CVERecord?id=CVE-2026-35572
Post summary
The post announces an SSRF vulnerability (CVE‑2026‑35572) in ChurchCRM versions prior to 6.5.3, providing technical details but no PoC, exploit code, or patch information.
