
CVE-2026-39318 ChurchCRM is an open-source church management system. Prior to 7.1.0, the GroupPropsFormRowOps.php file contains a SQL injection vulnerability. User input in the Fiel… https://www.cve.org/CVERecord?id=CVE-2026-39318
Post summary
The tweet discloses a SQL injection vulnerability in ChurchCRM’s GroupPropsFormRowOps.php (pre‑7.1.0), with no PoC, exploit, or patch details provided.

