CVE-2026-39342
ChurchCRM versions before 7.1.0 allow attackers who can run advanced searches to inject SQL through the searchwhat parameter. This can let them read or modify the database. The issue is fixed in 7.1.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of ChurchCRM 7.0.x and earlier who have access to the Data/Reports > Query Menu and the Advanced Search query.
Real-world impact
An attacker who can run advanced searches could inject SQL commands, potentially reading sensitive data, modifying records, or deleting data in the ChurchCRM database.
Why this severity
The CVSS score of 9.4 reflects that the vulnerability is exploitable over the network, requires only low authentication, and gives attackers high impact on confidentiality, integrity, and availability of the database.
What to do about it
- 01Upgrade ChurchCRM to version 7.1.0 or later.
- 02Restart the web server or application after the upgrade.
NVD-referenced vendor advisory
Timeline
- Apr 7, 2026 · Apr 7, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/ChurchCRM/CRM/security/advi…exploitvendor advisory