
🚨 CVE-2026-39342: ChurchCRM has a SQL injection se... ChurchCRM's QueryView.php lets auth'd users dump entire databases via searchwhat param - 9.4 CVSS means your congregati... https://zerodaysignal.com/vulnerability/CVE-2026-39342 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces a critical SQL injection in ChurchCRM's QueryView.php, allowing authenticated users to export full databases, with a CVSS score of 9.4.

