8.1

CVSS3.1

CVE-2026-39331 - ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spamโ€ฆ

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} parameter in requests, regardless of whether they possess the required EditRecords privilege. /family/{โ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:36 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:58 p.m.

8.8

CVSS3.1

CVE-2026-39330 - ChurchCRM has a Blind SQL injection in PropertyAssign.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authenticated users with the role Manage Groups & Roles (ManageGroups) and Edit Records (isEditRecordsEnabled) can inject arbitrary SQL stโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:34 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:55 p.m.

8.8

CVSS3.1

CVE-2026-39329 - ChurchCRM has a Blind SQL injection in EventNames.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. Authenticated users with AddEvent privileges can inject SQL via the newEvtTypeCntLst parameter during event type creation. The vulnerable flow reachesโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:33 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:58 p.m.

8.9

CVSS3.1

CVE-2026-39328 - ChurchCRM has Stored XSS in Social Profile Fields

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and โ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:56 p.m.

8.8

CVSS3.1

CVE-2026-39327 - ChurchCRM has a SQL injection in MemberRoleChange.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in ChurchCRM 7.0.5. Authenticated users with the role Manage Groups & Roles (ManageGroups) can inject arbitrary SQL statements through the NewRole parโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:31 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:56 p.m.

8.8

CVSS3.1

CVE-2026-39326 - ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled can inject arbitrary SQL statements through the Name and Description parametersโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:30 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:58 p.m.

7.2

CVSS3.1

CVE-2026-39325 - ChurchCRM has a Blind SQL injection in SettingsUser.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in ChurchCRM 7.0.5. Authenticated administrative users can inject arbitrary SQL statements through the type array parameter via the index and thus extractโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:29 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:57 p.m.

0.0

CVE-2026-39323 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39326. Reason: This candidate is a duplicate of CVE-2026-39326. Notes: All CVE users should reference CVE-2026-39326 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidentโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:28 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:17 p.m.

8.8

CVSS3.1

CVE-2026-39318 - ChurchCRM has a DDL SQL Injection in GroupPropsFormRowOps.php

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRowOps.php`. A user has to be authenticated. For `ManageGroups` privileges have toโ€ฆ

๐Ÿ“… Published: April 7, 2026, 5:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:20 p.m.

6.1

CVSS3.1

CVE-2026-39335 - ChurchCRM has Stored XSS via Unescaped data-* Attributes in Group/Family Controls

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily an admin-to-admin stored XSS path when writable entity fields are abused. This vulnerability is fixed in 7.1.1.

๐Ÿ“… Published: April 7, 2026, 5:23 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 9:41 a.m.
Total resulsts: 344980
Page 211 of 34,498
ยซ previous page ยป next page
Filters