
CVE-2026-35567 ChurchCRM is an open-source church management system. Prior to 7.1.0, the NewRole POST parameter in src/MemberRoleChange.php is used in an SQL query without proper in… https://www.cve.org/CVERecord?id=CVE-2026-35567
Post summary
The post reports that ChurchCRM versions prior to 7.1.0 contain an SQL injection flaw in src/MemberRoleChange.php via the NewRole POST parameter.


