SQL injection in ChurchCRM - CVE-2026-39342
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the QueryView.php searchwhat parameter when handling requests to QueryView.php with QueryID=15. A remote user can send a specially crafted request to disclose sensitive information.
Exploitation requires access to Data/Reports > Query Menu and the Advanced Search query.