CVE-2023-29842: Churchcrm

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

Affected products

Published 2023-05-04. Last modified 2026-06-17.