Kaitan ID Security[verified]@KaitanSecurityDisclosure
The tweet alerts on a newly disclosed CVE-2026-42289 in ChurchCRM, providing a high CVSS score and a link to an analysis, but offers no deeper technical or exploitation information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post reveals a CVE‑2026‑42289 CSRF flaw in ChurchCRM before version 7.3.2, offering minimal technical details and no indications of exploitation or mitigation.
CVE@CVEnewDisclosure
The post discloses CVE‑2026‑42289, describing how ChurchCRM’s UserEditor.php processes user account creation via $_POST and notes that the issue is addressed in version 7.3.2.