
CVE-2026-40482 ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAn… https://www.cve.org/CVERecord?id=CVE-2026-40482
Post summary
The post discloses a SQL injection vulnerability affecting ChurchCRM versions before 7.2.0, detailing the affected function but providing no exploit code or patch information.
