
CVE-2026-40582 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before … https://www.cve.org/CVERecord?id=CVE-2026-40582
Post summary
A brief disclosure notes that CVE‑2026‑40582 affects ChurchCRM versions before 7.2.0 via the /api/public/user/login endpoint, but offers no technical details, PoC, or patch information.

