
CVE-2026-39343 ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEventTypes.php file, which is only accessible to… https://www.cve.org/CVERecord?id=CVE-2026-39343
Post summary
A SQL injection flaw was disclosed in ChurchCRM’s EditEventTypes.php, affecting all releases before 7.1.0.
