CVE-2026-35567 | ChurchCRM up to 7.0.x PersonView Page src/MemberRoleChange.php src sql injection
A vulnerability was found in ChurchCRM up to 7.0.x. It has been rated as critical. This affects the function src of the file src/MemberRoleChange.php of the component PersonView Page. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-35567. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.