PatchSiren cyber security CVE debrief
CVE-2026-35184 phili67 CVE debrief
EcclesiaCRM, a church management software, has a SQL injection vulnerability prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. Users should review the CVE record and NVD details for additional information. The vulnerability has a high CVSS score of 8.7, indicating a high severity. Affected users should apply the patch to prevent SQL injection attacks. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then.
- Vendor
- phili67
- Product
- ecclesiacrm
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Users of EcclesiaCRM prior to version 8.0.0 should apply the patch to prevent SQL injection attacks. This includes administrators and security teams responsible for managing and securing EcclesiaCRM deployments. Additionally, operators and platform teams should review the CVE record and NVD details to understand the affected scope and severity. Vulnerability management and security teams should prioritize this vulnerability due to its high CVSS score and availability of a patch.
Technical summary
CVE-2026-35184 is a SQL injection vulnerability in EcclesiaCRM, a church management software, prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. The vulnerability has a high CVSS score of 8.7, indicating a high severity. Users of EcclesiaCRM prior to version 8.0.0 should apply the patch to prevent SQL injection attacks. The vulnerability can be mitigated by reviewing and monitoring database queries for suspicious activity and implementing additional security measures to prevent SQL injection attacks.
Defensive priority
High priority due to the high CVSS score of 8.7 and the availability of a patch.
Recommended defensive actions
- Apply the patch by upgrading to EcclesiaCRM version 8.0.0 or later.
- Review and monitor database queries for suspicious activity.
- Implement additional security measures to prevent SQL injection attacks.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD details provide evidence of the vulnerability and its fix. Additional information from the source item and references supports the existence of the vulnerability and the availability of a patch. The vulnerability has a high CVSS score of 8.7, indicating a high severity. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then. The NVD entry is currently Analyzed.
Official resources
-
CVE-2026-35184 CVE record
CVE.org
-
CVE-2026-35184 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Issue Tracking, Patch
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T20:16:26.880Z and has not been modified since then.