EXPOSURES › CVE-2026-35184
CVE-2026-35184
CRITICAL
DETAIL
SourceNVD · cve
Published2026-04-06
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-35184 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.