CVE-2026-24854Disclosure(churchcrm / churchcrm)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch churchcrm churchcrm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-01-30: 3Mentions · 2026-01-31: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-01-31: 1Technical Details · 2026-01-30: 3Technical Details · 2026-01-31: 101-3001-31
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-303
Disclosure2Patch1
2026-01-311
Patch1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A high-severity SQL injection flaw (CVE-2026-24854) affects Church CRM's PaddleNumEditor.php. This can lead to database compromise. Review fixes and apply updates. #SQLi #ChurchCRM #infosec https://www.pulsepatch.io/posts/cve-2026-24854-church-crm-sql-injection

    Post summary

    A high‑severity SQL injection vulnerability (CVE‑2026‑24854) in Church CRM’s PaddleNumEditor.php can compromise the database; patching is recommended.

    0000067
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24854 SQL Injection in ChurchCRM Prior to 6.7.2 via Authenticated `/Pad... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24854 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    Announces CVE‑2026‑24854 as a SQL injection in ChurchCRM prior to version 6.7.2, providing a link for more details, with no exploit or patch information included.

    0000042
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24854: HIGH] Critical SQL Injection vulnerability in ChurchCRM prior to version 6.7.2 allows any authenticated user to exploit it through the `PerID` parameter. Update to version 6.7.2 for security.#cve,CVE-2026-24854,#cybersecurity https://cvefind.com/CVE-2026-24854

    Post summary

    The advisory announces a critical SQL injection in ChurchCRM that any authenticated user can exploit via the PerID parameter and advises upgrading to v6.7.2.

    0000062
    584 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24854 ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any… https://www.cve.org/CVERecord?id=CVE-2026-24854

    Post summary

    The post discloses a SQL injection flaw in ChurchCRM (CVE-2026-24854) affecting versions before 6.7.2, but it contains no exploit code, patch details, or evidence of active exploitation.

    00000152
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more