2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39333 — Churchcrm Churchcrm: This constitutes a reflected XSS vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39333

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious URL that executes arbitrary JavaScript when visited by another authenticated user. This constitutes a reflected XSS vulnerability. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDChurchcrmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39332 — Churchcrm Churchcrm: Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39332

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocus with no user interaction required, an attacker can steal session cookies and fully take over any victim account, including administrator accounts, by tricking them into submitting CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDChurchcrmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39331 — Churchcrm Churchcrm: Prior to 7.1.0, an authenticated API user can modify any family record's state without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39331

ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family record's state without proper authorization by simply changing the {familyId} parameter in requests, regardless of whether they possess the required EditRecords privilege. /family/{familyId}/verify, /family/{familyId}/verify/url, /family/{familyId}/verify/now, /family/{familyId}/activate/{status}, and /family/{familyId}/geocode lack role-based access control, CVSSv3.1 8.1 (HIGH)

CWECWE 639CWECWE 863VNDChurchcrmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39330 — Churchcrm Churchcrm: Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39330

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyAssign.php in ChurchCRM. Authenticated users with the role Manage Groups & Roles (ManageGroups) and Edit Records (isEditRecordsEnabled) can inject arbitrary SQL statements through the Value parameter and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39329 — Churchcrm Churchcrm: Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39329

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /EventNames.php in ChurchCRM. Authenticated users with AddEvent privileges can inject SQL via the newEvtTypeCntLst parameter during event type creation. The vulnerable flow reaches an ON DUPLICATE KEY UPDATE clause where unescaped user input is interpolated directly. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39328 — Churchcrm Churchcrm: Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39328

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Due to a 50-character field limit, the payload is distributed across all three fields and chains their onfocus event handlers to execute in sequence. When any user CVSSv3.1 8.9 (HIGH)

CWECWE 79VNDChurchcrmTYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39327 — Churchcrm Churchcrm: Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39327

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in ChurchCRM 7.0.5. Authenticated users with the role Manage Groups & Roles (ManageGroups) can inject arbitrary SQL statements through the NewRole parameter and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39326 — Churchcrm Churchcrm: Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39326

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled can inject arbitrary SQL statements through the Name and Description parameters and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39319 — Churchcrm Churchcrm: Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39319

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users can inject arbitrary SQL statements through the iCurrentFundraiser PHP session parameter and thus extract and modify information from the database. This vulnerability is fixed in 7.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-39318 — ChurchCRM: Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39318

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRowOps.php`. A user has to be authenticated. For `ManageGroups` privileges have to be enabled and for the other two endpoints the attack has to be executed by an administrative user. These users can inject arbitrary SQL statements through the `Field` parameter an CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDChurchcrmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-35576 — Churchcrm Churchcrm: Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35576

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated user to inject arbitrary JavaScript code via dynamically assigned person properties. The malicious payload is persistently stored and executed when other users view the affected person profile or access t CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDChurchcrmTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 18:16Z
HIGH

CVE-2026-35575 — Churchcrm Churchcrm: Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35575

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator views the page. This enables attackers to steal the administrator’s session cookies, potentially leading to full administrative account takeover. This vulnerability is fixed in 6.5. CVSSv3.1 8.0 (HIGH)

CWECWE 79CWECWE 1004VNDChurchcrmTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-07
2026-04-07 18:16Z
CRIT

CVE-2026-35573 — Churchcrm Churchcrm: Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability exists in src/ChurchCRM/Backup/RestoreJob.php. The $rawUploadedFile['name'] parameter is user-controlled and allows uploading files with arbitrary names to /var/www/htm CVSSv3.1 9.1 (CRITICAL)

CWECWE 434CWECWE 22VNDChurchcrmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 18:16Z
CRIT

CVE-2026-31272 — Mrcms Mrcms: 3.1.2 contains an access control vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31272

MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDMrcmsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 18:16Z
CRIT

CVE-2026-31271 — megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31271

megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The insert() method in UserController.java lacks authentication checks, allowing unauthenticated attackers to create super administrator accounts by directly accessing the /user/insert endpoint. This leads to complete system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 288TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2026-4631 — The injection occurs during the authentication flow before any credential verification takes place, meaning

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4631

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification t CVSSv3.1 9.8 (CRITICAL)

CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 17:16Z
HIGH

CVE-2026-39307 — PraisonAI: Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip"

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39307

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's zipfile.extractall() without verifying if the files within the archive resolve outside of the intended extraction directory. This vulnerability is fixed in 1.5.113. CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2026-39305 — PraisonAI: Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39305

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sensitive system files or drop executable payloads on the host. This vulnerability is fixed in 1.5.113. CVSSv3.1 9.0 (CRITICAL)

CWECWE 22VNDPraisonaiTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2026-35614 — Frappe Frappe: Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35614

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fixed in 16.14.0 and 15.104.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDFrappeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-07
2026-04-07 17:16Z
HIGH

CVE-2026-35610 — PolarLearn: In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module used an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35610

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module used an inverted admin check. Because of the inverted condition, authenticated non-admin users were allowed to execute both actions, while real admins were rejected. This is a direct privilege-escalation issue in the application. CVSSv3.1 8.8 (HIGH)

CWECWE 285VNDPolarlearnTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 17:16Z
HIGH

CVE-2026-35607 — File: Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms")

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35607

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the signup handler. The same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth login are granted execution capabilities from global default CVSSv3.1 8.1 (HIGH)

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2026-35580 — Emissary: Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35580

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access could inject arbitrary shell commands, leading to repository poisoning and supply chain compromise affecting all downstream users. This vulnerability is fixed in 8.39.0. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77VNDEmissaryTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-07
2026-04-07 17:16Z
HIGH

CVE-2026-27314 — Privilege: escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27314

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recommended to upgrade to version 5.0.7+, which fixes this issue. CVSSv3.1 8.8 (HIGH)

CWECWE 267TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-07
2026-04-07 17:16Z
CRIT

CVE-2026-23696 — Windmill: CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23696

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and administrative user identifiers, forge an administrative token, and then execute arbitrary code via the workflow execution endpoints. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDWindmillTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-07
2026-04-07 17:16Z
HIGH

CVE-2026-22683 — Nextcloud Flow: Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22683

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not enforce the Operator restriction on workspace endpoints, allowing an Operator to create and update scripts, flows, apps, and raw_apps. Since Operators can also execut CVSSv3.1 8.8 (HIGH) · EPSS 51th percentile

CWECWE 862VNDWindmillVNDNextcloudTYPVulnerability
8.8
CVSS v3.1
94
Edit Score