ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25891.json"