SQL Injection Vulnerability in ChurchCRM Management System
CVE-2026-39342
9.4CRITICAL
What is CVE-2026-39342?
ChurchCRM, an open-source church management system, has a vulnerability where the 'searchwhat' parameter in QueryView.php with QueryID=15 allows for SQL injection attacks. This issue requires an authenticated user to have access to the Data/Reports > Query Menu and the 'Advanced Search' query. The vulnerability is resolved in version 7.1.0.
Affected Version(s)
CRM < 7.1.0
