CVE-2026-39342
ChurchCRM CRM, churchcrm
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.
- CVSS
- 9.4
- EPSS
- 0.31% 23.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.08