Critical exposure
CVE-2026-42288 ChurchCRM is an open-source church management system.
- CVSS 10
- Remote code execution exposure
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.