PWPN A.I CyberSecurity Scoring
PWPN
Company Information
Website:https://popesprayer.va
Employees number:16
Number of followers:0
NAICS:8131
Industry Type:Religious Institutions
Homepage:popesprayer.va
PWPN Risk Score (AI oriented)
Between 800 and 849
PWPNReligious Institutions
Updated:
28/07/2026
28/07/2026
804/1000
Good
A
PWPN Global Score (TPRM)
xxxx
PWPNReligious Institutions
Score locked

PWPNGood
Current Score
804A (GOOD)
01000
1 incidents
-12 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
805
JULY 2026
804
JUNE 2026
804
MAY 2026
804
APRIL 2026
804
MARCH 2026
804
FEBRUARY 2026
804
JANUARY 2026
815
Vulnerability
03 Jan 2026 • PWPN
Pope’s Worldwide Prayer Network: Vatican’s Click To Pray app exposed personal data from 700,000 users
Vatican’s Click To Pray App Exposed User Data Due to API Flaws
803
CRITICAL-12
POP1785241904
Vatican’s Click To Pray App Exposed User Data Due to API Flaws
A security vulnerability in Click To Pray, a prayer app launched by Pope Francis in 2019, exposed the personal data of over 700,000 users before being fixed earlier this year. The app, developed by La Machi Communication for Good Causes for the Pope’s Worldwide Prayer Network, offers daily prayers and a digital prayer community.
Independent researcher BobDaHacker discovered two critical flaws in the app’s API in January 2026. The first was an Insecure Direct Object Reference (IDOR) vulnerability, where the API returned user records including email addresses, full names, countries, and dates of birth to anyone who requested them, without proper authorization checks. The app assigned sequential numeric IDs to users, allowing attackers to cycle through all 719,517 registered accounts.
A second flaw compounded the risk: the API exposed validation hashes in email verification responses, enabling attackers to hijack accounts by registering with an email they didn’t own and verifying it before the legitimate user could.
Despite reporting the issue to nine different email addresses associated with the app and the Vatican, the researcher received no response. The flaws were only addressed after a journalist intervened, highlighting gaps in the Vatican’s vulnerability disclosure process.
This isn’t the first security lapse involving a Vatican-affiliated app. In 2019, a flaw in the eRosary app exposed login PINs in plaintext, allowing account takeovers a similar issue to the one found in Click To Pray.
While Vatican City introduced its own data protection regulation (Decree No. DCLVII) in April 2024, it remains unclear whether it applies to the app or its operators. The exposed data, which may have been circulating for months, increases the risk of phishing attacks, particularly since the app’s emails failed standard authentication checks, making impersonation easier.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
815
NOVEMBER 2025
815
OCTOBER 2025
815
SEPTEMBER 2025
815
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for PWPN ??
What was PWPN's A.I Rankiteo Cyber Score in July 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in June 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in May 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in April 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in March 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in February 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in January 2026 ??
What was PWPN's A.I Rankiteo Cyber Score in December 2025 ??
What was PWPN's A.I Rankiteo Cyber Score in November 2025 ??
What was PWPN's A.I Rankiteo Cyber Score in October 2025 ??
What was PWPN's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on PWPN's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with PWPN ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view PWPN's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?