CVE-2026-39331 — ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} — CVE Database · The Intelligence Room