
CVE-2026-39330 ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authe… https://www.cve.org/CVERecord?id=CVE-2026-39330
Post summary
The post discloses that CVE-2026-39330 is an SQL injection flaw in ChurchCRM’s /PropertyAssign.php endpoint on versions older than 7.1.0, but it provides no PoC, exploit, patch, or evidence of active exploitation.

