PT-2026-5407 · Churchcrm · Churchcrm

Sonntb21Dcat164

·

Published

2026-01-30

·

Updated

2026-02-17

·

CVE-2026-24854

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.7.2
Description ChurchCRM is an open-source church management system. A SQL Injection issue exists in the /PaddleNumEditor.php endpoint. Any authenticated user, even with limited permissions, can exploit SQL injection through the PerID parameter.
Recommendations Update to version 6.7.2.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-24854
GHSA-P3Q7-Q68Q-H2GR

Affected Products

Churchcrm