CVE-2026-40482 - ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`
CVE ID :CVE-2026-40482
Published : April 17, 2026, 10:58 p.m. | 1 hour, 12 minutes ago
Description :ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 17, 2026, 10:58 p.m. | 1 hour, 12 minutes ago
Description :ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...