Stored XSS Vulnerability in ChurchCRM Affects Admin Panel Functionality
CVE-2026-35575
8HIGH
What is CVE-2026-35575?
The ChurchCRM platform, known for its open-source church management capabilities, has a vulnerability affecting its admin panel's group-creation feature. Users with group-creation privileges can exploit this flaw by injecting harmful JavaScript code that triggers when an administrator accesses the affected page. This can lead to serious risks, including the potential theft of session cookies, putting the administrator's account at risk of complete takeover. The issue has been addressed in version 6.5.3 of ChurchCRM.
Affected Version(s)
CRM < 6.5.3
