Reflected XSS Vulnerability in ChurchCRM by ChurchCRM
CVE-2026-39332
8.7HIGH
What is CVE-2026-39332?
ChurchCRM, an open-source church management system, is impacted by a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php. This flaw allows any authenticated user to execute malicious JavaScript in the browser of other authenticated users. Due to the payload's automatic execution via autofocus, user interaction is not required. An attacker can exploit this vulnerability to steal session cookies, enabling full control over victim accounts, including those of administrators. This issue has been rectified in version 7.1.0. For more information, visit ChurchCRM Security Advisory.
Affected Version(s)
CRM < 7.1.0
