Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2935 articles · 104969 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-35566PATCHED
ChurchCRM · CRM

ChurchCRM has a SQL Injection via Unquoted Session Value in FundRaiserStatement.php

Description

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical SQL injection vulnerability exists in src/Reports/FundRaiserStatement.php where the $_SESSION['iCurrentFundraiser'] value is used in an unquoted numeric SQL context without integer validation. The value originates from src/FundRaiserEditor.php where InputUtils::legacyFilterInputArr() is called without the 'int' type specifier. This vulnerability is fixed in 7.1.0.

Affected Products

VendorProductVersions
ChurchCRMCRM< 7.1.0

References

  • https://github.com/ChurchCRM/CRM/security/advisories/GHSA-grq6-q49f-44xh(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB5h ago
CVE-2026-35566 | ChurchCRM up to 7.0.x FundRaiserStatement.php legacyFilterInputArr iCurrentFundraiser sql injection
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
7.1.0
CWECWE-89
PublishedApr 7, 2026
Last enriched4h agov2
Tags
CVE-2026-35566
Trending Score27
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-39330EXP
ChurchCRM has a Blind SQL injection in PropertyAssign.php
Trending: 62
CRITICALCVE-2026-39334EXP
ChurchCRM has a Blind SQL injection in SettingsIndividual.php
Trending: 62
HIGHCVE-2026-39327EXP
ChurchCRM has a SQL injection in MemberRoleChange.php
Trending: 59
HIGHCVE-2026-39326EXP
ChurchCRM has a Blind SQL injection in PropertyTypeEditor.php
Trending: 59
HIGHCVE-2026-39329EXP
ChurchCRM has a Blind SQL injection in EventNames.php
Trending: 59

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Updated: affectedVersions, patchAvailable, tags
Apr 7, 2026
Patch Available
Apr 7, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated description with new technical details, changed affected versions to < 7.0.0, updated severity to CRITICAL, and added CVE-2026-35566 as a tag.

affectedVersionspatchAvailabletags
via VulDB
v14h ago

Initial creation