SQL injection in ChurchCRM - CVE-2026-39341
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to manipulate the database and disclose sensitive information.
The vulnerability exists due to SQL injection in the Reports/ConfirmReportEmail.php endpoint when handling the familyId parameter in requests. A remote user can send a specially crafted request to manipulate the database and disclose sensitive information.
Exploitation requires access to the vulnerable endpoint.