9.4

CVSS4.0

CVE-2026-39342 - ChurchCRM has a SQL injection searchwhat parameter via QueryView.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is…

πŸ“… Published: April 7, 2026, 6:02 p.m. πŸ”„ Last Modified: April 9, 2026, 4:02 p.m.

8.1

CVSS3.1

CVE-2026-39341 - SQL injection in ChurchCRM.0

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not use…

πŸ“… Published: April 7, 2026, 6:01 p.m. πŸ”„ Last Modified: April 9, 2026, 3:35 p.m.

8.1

CVSS3.1

CVE-2026-39340 - ChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer Substitution

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration functionality for managing property type categories (People β†’ Person Properties / Family Properties). The vulnerability was introduced whe…

πŸ“… Published: April 7, 2026, 6 p.m. πŸ”„ Last Modified: April 9, 2026, 6:43 p.m.

9.1

CVSS3.1

CVE-2026-39339 - ChurchCRM has an API Authentication Bypass

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywher…

πŸ“… Published: April 7, 2026, 5:58 p.m. πŸ”„ Last Modified: April 8, 2026, 7:46 p.m.

8.6

CVSS4.0

CVE-2026-39338 - ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser's D…

πŸ“… Published: April 7, 2026, 5:57 p.m. πŸ”„ Last Modified: April 9, 2026, 3:53 p.m.

6.1

CVSS3.1

CVE-2026-39336 - ChurchCRM has Stored XSS from unescaped config values in HTML attributes

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, Person editor defaults rendered into address fields, and external self-registration form defaults. This is primarily an admin-to-admin…

πŸ“… Published: April 7, 2026, 5:40 p.m. πŸ”„ Last Modified: April 8, 2026, 7:47 p.m.

8.8

CVSS3.1

CVE-2026-39334 - ChurchCRM has a Blind SQL injection in SettingsIndividual.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsIndividual.php in ChurchCRM 7.0.5. Authenticated users without any specific privileges can inject arbitrary SQL statements through the type array parameter via the…

πŸ“… Published: April 7, 2026, 5:38 p.m. πŸ”„ Last Modified: April 8, 2026, 7:47 p.m.

8.7

CVSS3.1

CVE-2026-39333 - ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious U…

πŸ“… Published: April 7, 2026, 5:38 p.m. πŸ”„ Last Modified: April 8, 2026, 7:47 p.m.

8.7

CVSS3.1

CVE-2026-39332 - ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocu…

πŸ“… Published: April 7, 2026, 5:37 p.m. πŸ”„ Last Modified: April 8, 2026, 7:47 p.m.

8.1

CVSS3.1

CVE-2026-39331 - ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam…

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} parameter in requests, regardless of whether they possess the required EditRecords privilege. /family/{…

πŸ“… Published: April 7, 2026, 5:36 p.m. πŸ”„ Last Modified: April 8, 2026, 7:47 p.m.
Total resulsts: 343552
Page 74 of 34,356
Β« previous page Β» next page
Filters