PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35184 phili67 CVE debrief

EcclesiaCRM, a church management software, has a SQL injection vulnerability prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. Users should review the CVE record and NVD details for additional information. The vulnerability has a high CVSS score of 8.7, indicating a high severity. Affected users should apply the patch to prevent SQL injection attacks. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then.

Vendor
phili67
Product
ecclesiacrm
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Users of EcclesiaCRM prior to version 8.0.0 should apply the patch to prevent SQL injection attacks. This includes administrators and security teams responsible for managing and securing EcclesiaCRM deployments. Additionally, operators and platform teams should review the CVE record and NVD details to understand the affected scope and severity. Vulnerability management and security teams should prioritize this vulnerability due to its high CVSS score and availability of a patch.

Technical summary

CVE-2026-35184 is a SQL injection vulnerability in EcclesiaCRM, a church management software, prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. The vulnerability has a high CVSS score of 8.7, indicating a high severity. Users of EcclesiaCRM prior to version 8.0.0 should apply the patch to prevent SQL injection attacks. The vulnerability can be mitigated by reviewing and monitoring database queries for suspicious activity and implementing additional security measures to prevent SQL injection attacks.

Defensive priority

High priority due to the high CVSS score of 8.7 and the availability of a patch.

Recommended defensive actions

  • Apply the patch by upgrading to EcclesiaCRM version 8.0.0 or later.
  • Review and monitor database queries for suspicious activity.
  • Implement additional security measures to prevent SQL injection attacks.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD details provide evidence of the vulnerability and its fix. Additional information from the source item and references supports the existence of the vulnerability and the availability of a patch. The vulnerability has a high CVSS score of 8.7, indicating a high severity. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then. The NVD entry is currently Analyzed.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then.