CVE-2026-39341: Churchcrm
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL injection due to an improper input validation. Endpoint Reports/ConfirmReportEmail.php?familyId= is not correctly sanitising user input, specifically, the sanitised input is not used to create the SQL query. This vulnerability is fixed in 7.1.0.
Affected products
- Churchcrm Churchcrm: before 7.1.0 (fixed in 7.1.0)
Published 2026-04-07. Last modified 2026-07-24.