6.3

CVSS4.0

CVE-2026-39321 - Parse Server has a login timing side-channel reveals user existence

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the se…

πŸ“… Published: April 7, 2026, 6:11 p.m. πŸ”„ Last Modified: April 15, 2026, 5:20 p.m.

10

CVSS3.1

CVE-2026-39337 - ChurchCRM Affected by Unauthenticated RCE in Install Wizard

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server comprom…

πŸ“… Published: April 7, 2026, 6:08 p.m. πŸ”„ Last Modified: April 13, 2026, 2:26 p.m.

8.8

CVSS3.1

CVE-2026-39319 - ChurchCRM has a Second Order SQLI via FundRaiserEditor.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users can inject arbitrary SQL statements through the …

πŸ“… Published: April 7, 2026, 6:05 p.m. πŸ”„ Last Modified: April 10, 2026, 8:57 p.m.

8.1

CVSS3.0

CVE-2026-39344 - Reflected XSS the login page through the 'username' parameter

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the username parameter received from the URL. The username parameter value is directly di…

πŸ“… Published: April 7, 2026, 6:04 p.m. πŸ”„ Last Modified: April 10, 2026, 9:41 a.m.

7.2

CVSS3.1

CVE-2026-39343 - ChurchCRM has a SQL Injection in Event Type Editor (Admin)

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is only accessible to administrators. The EN_tyid POST parameter is not sanitized before being used in a SQL query, allowing an administrator to execute a…

πŸ“… Published: April 7, 2026, 6:03 p.m. πŸ”„ Last Modified: April 10, 2026, 7:51 p.m.

9.4

CVSS4.0

CVE-2026-39342 - ChurchCRM has a SQL injection searchwhat parameter via QueryView.php

ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is…

πŸ“… Published: April 7, 2026, 6:02 p.m. πŸ”„ Last Modified: April 10, 2026, 7:52 p.m.

8.1

CVSS3.1

CVE-2026-39341 - SQL injection in ChurchCRM.0

ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not use…

πŸ“… Published: April 7, 2026, 6:01 p.m. πŸ”„ Last Modified: April 15, 2026, 8:09 p.m.

8.1

CVSS3.1

CVE-2026-39340 - ChurchCRM has a SQL Injection in PropertyTypeEditor.php via Incorrect Sanitizer Substitution

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration functionality for managing property type categories (People β†’ Person Properties / Family Properties). The vulnerability was introduced whe…

πŸ“… Published: April 7, 2026, 6 p.m. πŸ”„ Last Modified: April 10, 2026, 9:41 a.m.

9.1

CVSS3.1

CVE-2026-39339 - ChurchCRM has an API Authentication Bypass

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public" anywher…

πŸ“… Published: April 7, 2026, 5:58 p.m. πŸ”„ Last Modified: April 13, 2026, 2:26 p.m.

8.6

CVSS4.0

CVE-2026-39338 - ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied input prior to rendering it within the browser's D…

πŸ“… Published: April 7, 2026, 5:57 p.m. πŸ”„ Last Modified: April 15, 2026, 8:15 p.m.
Total resulsts: 349182
Page 626 of 34,919
Β« previous page Β» next page
Filters