Report: CVE-2026-40482 - ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanS

Report: CVE-2026-40482 - ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanS

CVE ID :CVE-2026-40482 Published : April 18, 2026, 12:16 a.m. | 1 hour, 15 minutes ago Description :ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
April 18, 2026
Impact: SQL injection