High severity8.1NVD Advisory· Published Apr 7, 2026· Updated Apr 15, 2026
CVE-2026-39341
CVE-2026-39341
Description
ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/ChurchCRM/CRM/security/advisories/GHSA-3h69-vjff-jj5cnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.