NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-40482
Summary

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.

Publication Date April 18, 2026, 9:16 a.m.
Registration Date April 19, 2026, 4:08 a.m.
Last Update April 18, 2026, 9:16 a.m.
Related information, measures and tools
Common Vulnerabilities List