CVE-2026-40482
- EPSS 0.03%
- Veröffentlicht 17.04.2026 22:58:48
- Zuletzt bearbeitet 18.04.2026 00:16:39
ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.
CVE-2026-39940
- EPSS 0.04%
- Veröffentlicht 13.04.2026 16:34:58
- Zuletzt bearbeitet 17.04.2026 15:33:34
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a link that, when visited by an authenticated user, would redirect them to any URL chosen by an attacker i...
CVE-2026-39941
- EPSS 0.07%
- Veröffentlicht 09.04.2026 15:38:07
- Zuletzt bearbeitet 14.04.2026 14:44:01
ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and EDesc parameters in EditEventAttendees.php to be rendered in a page without proper output encoding, ena...
CVE-2026-39340
- EPSS 0.03%
- Veröffentlicht 07.04.2026 18:16:46
- Zuletzt bearbeitet 09.04.2026 18:43:44
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTypeEditor.php, part of the administration functionality for managing property type categories (People → Person Properties / Family ...
CVE-2026-39341
- EPSS 0.03%
- Veröffentlicht 07.04.2026 18:16:46
- Zuletzt bearbeitet 15.04.2026 20:09:52
ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user in...
CVE-2026-39342
- EPSS 0.03%
- Veröffentlicht 07.04.2026 18:16:46
- Zuletzt bearbeitet 10.04.2026 19:52:09
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to t...
CVE-2026-39343
- EPSS 0.03%
- Veröffentlicht 07.04.2026 18:16:46
- Zuletzt bearbeitet 10.04.2026 19:51:15
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is only accessible to administrators. The EN_tyid POST parameter is not sanitized before being used in a ...
CVE-2026-39344
- EPSS 0.04%
- Veröffentlicht 07.04.2026 18:16:46
- Zuletzt bearbeitet 09.04.2026 18:42:28
ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the username parameter received from the...
- EPSS 0.27%
- Veröffentlicht 07.04.2026 18:16:45
- Zuletzt bearbeitet 10.04.2026 20:57:31
ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial install...
CVE-2026-39338
- EPSS 0.08%
- Veröffentlicht 07.04.2026 18:16:45
- Zuletzt bearbeitet 15.04.2026 20:15:01
ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM dashboard. The application fails to sanitize or encode user-supplied i...