github.comConfirmation
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-7fr4-mvfm-cxfx CVE-2026-39342
CRITICAL
ChurchCRM has a SQL injection searchwhat parameter via QueryView.php
Record summary
CVE-2026-39342 has a selected CVSS score of 9.4 (critical).
Description
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with the QueryID=15 is vulnerable to a SQL injection. The authenticated user requires access to Data/Reports > Query Menu and access to the "Advanced Search" query. This vulnerability is fixed in 7.1.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 7.1.0 | affected |