Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-39343

HIGH NVD
CVSS Score 7.2
Severity HIGH
Published Apr 07, 2026
Vendor unknown

Description

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is only accessible to administrators. The EN_tyid POST parameter is not sanitized before being used in a SQL query, allowing an administrator to execute arbitrary SQL commands directly against the database. This vulnerability is fixed in 7.1.0.

References