SQL Injection Vulnerability in ChurchCRM Open-Source Management System
CVE-2026-40482

7.1HIGH

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
17 April 2026

What is CVE-2026-40482?

ChurchCRM, an open-source church management system, suffers from a SQL injection vulnerability that affects versions before 7.2.0. The flaw exists due to the unsanitized concatenation of the variable $routeAndAccount into raw SQL within the FinancialService::getMemberByScanString() function. This vulnerability could potentially allow attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information in the database. The issue has been addressed in version 7.2.0, emphasizing the importance of updating to this version to maintain security and safeguard user data.

Affected Version(s)

CRM < 7.2.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.