CVE-2026-35184
CRITICALEcclesiaCRM <8.0.0 queryview.php - SQL Injection
Title source: manualDescription
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/phili67/ecclesiacrm/security/advisories/GHSA-gjw3-73q9-v2qh
X_Refsource_Misc x_refsource_misc
https://github.com/phili67/ecclesiacrm/pull/2861
X_Refsource_Misc x_refsource_misc
https://github.com/phili67/ecclesiacrm/commit/f743b97f89da469a4c70b82bd61d0a59a3a957a9
X_Refsource_Misc x_refsource_misc
https://gist.github.com/NicolasPauferro/d877992327592f1e8eb4e2c9dce1ae9b
Scores
CVSS v3
9.8
EPSS
0.0035
EPSS Percentile
26.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (2)
ecclesiacrm/ecclesiacrm
< 8.0.0
phili67/ecclesiacrm
< 8.0.0
Published
Apr 06, 2026
Tracked Since
Apr 07, 2026