LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-39318

CVE-2026-39318 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 9, 2026

ChurchCRM - SQL Injection

Published: April 7, 2026Updated: April 9, 2026Remote Exploitable

Overview

ChurchCRM < 7.1.0 contains a SQL injection caused by improper sanitization of the Field parameter in GroupPropsFormRowOps.php, letting attackers execute arbitrary SQL statements, exploit requires crafted input.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 3.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary SQL statements, potentially leading to data disclosure, modification, or full database compromise.

Mitigation

Update to version 7.1.0 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 8, 2026

🟠 CVE-2026-39318 - High (8.8) ChurchCRM is an open-source church management system. Prior to 7.1.0, the GroupPropsFormRowOps.php file contains a SQL injection vulnerability. User input in the Field parameter is directly inserted into SQL queries without proper sanitization. Th... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-39318/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-39318
Severity
High
CVSS Score
8.8
Type
sql_injection
Status
unconfirmed
EPSS
3.0%
Social Posts
1

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

3.0%Probability of exploitation in the next 30 days