CVE-2026-24854highCWE-89

CVE-2026-24854: high-severity vulnerability in ChurchCRM CRM

Church CRM has SQL injection in PaddleNumEditor.php

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
ChurchCRM · CRM