Stored XSS Vulnerability in ChurchCRM Affects Admin Panel Functionality
CVE-2026-35575

8HIGH

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35575?

The ChurchCRM platform, known for its open-source church management capabilities, has a vulnerability affecting its admin panel's group-creation feature. Users with group-creation privileges can exploit this flaw by injecting harmful JavaScript code that triggers when an administrator accesses the affected page. This can lead to serious risks, including the potential theft of session cookies, putting the administrator's account at risk of complete takeover. The issue has been addressed in version 6.5.3 of ChurchCRM.

Affected Version(s)

CRM < 6.5.3

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.