Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-44418 1 Phili67 1 Ecclesiacrm 2026-05-13 N/A
EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query parameters that use non-standard validation types. This is caused by an incomplete fix for CVE-2026-35184.
CVE-2026-35184 2 Ecclesiacrm, Phili67 2 Ecclesiacrm, Ecclesiacrm 2026-04-16 9.8 Critical
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.