CVE-2026-24854
EUVD-2026-502330.01.2026, 16:16
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| churchcrm | churchcrm | 𝑥 < 6.7.2 |
𝑥
= Vulnerable software versions