Junglewise Threat Intelligence

CVE-2026-39342: ChurchCRM SQL injection in QueryView.php searchwhat parameter

CVE-2026-39342 · Severity: high · CVSS 8.8 · Published 2026-04-07

Technologies: ChurchCRM. Vendors: ChurchCRM.

Executive brief

ChurchCRM, an open-source church management system, is vulnerable to a security flaw in its reporting module. An authorized user with access to the advanced search features can execute unauthorized database commands. This could allow an attacker to steal sensitive member data, modify records, or disrupt the organization's operations.

Technical details

A SQL injection vulnerability exists in ChurchCRM prior to version 7.1.0 within the 'searchwhat' parameter of the QueryView.php component. The flaw is specifically exploitable when the QueryID is set to 15 (Advanced Search). An authenticated attacker with permissions to access the Data/Reports Query Menu can inject malicious SQL commands to bypass security controls. This can lead to full database extraction, data modification, or denial of service via time-based payloads. The issue is resolved in version 7.1.0 by improving input validation and parameter handling.

Affected products

  • ChurchCRM CRM < 7.1.0

Timeline

  • 2026-04-05: advisory: GitHub security advisory published by researcher
  • 2026-04-07: disclosed: CVE-2026-39342 published
  • 2026-04-07: patched: Fixed in version 7.1.0

References

Related threats