Cross-Site Scripting Vulnerability in ChurchCRM Affects Open Source Users
CVE-2026-32880

6.4MEDIUM

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-32880?

ChurchCRM, an open-source church management system, has a vulnerability that affects versions prior to 7.0.2. It allows admin users to edit JSON-type system settings, which can be exploited to inject a JavaScript payload. This payload can execute when any admin views the system settings, leading to potential unauthorized actions and exposure of sensitive information. The issue stems from unescaped and unsanitized JSON input processed in SystemSettings.php. The vulnerability has been addressed in version 7.0.2. For more details, refer to the advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CRM < 7.0.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.