PatchSiren

phili67 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH phili67 CVE published 2026-04-06

CVE-2026-35184

EcclesiaCRM, a church management software, has a SQL injection vulnerability prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. Users should review the CVE record and NVD details for additional information. The vulnerability has a high CVSS score of 8.7, indicating a high severity. [truncated]