HIGH
phili67
CVE published 2026-04-06
CVE-2026-35184
EcclesiaCRM, a church management software, has a SQL injection vulnerability prior to version 8.0.0. The vulnerability exists in the queryview.php file and can be exploited via the custom and value parameters. This issue has been fixed in version 8.0.0. Users should review the CVE record and NVD details for additional information. The vulnerability has a high CVSS score of 8.7, indicating a high severity. [truncated]