Stored XSS Vulnerability in ChurchCRM by ChurchCRM
CVE-2026-39335

6.1MEDIUM

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39335?

ChurchCRM, an open-source church management system, has a Stored XSS vulnerability in the group remove control and family editor for state/country fields. This issue primarily affects admin-to-admin interactions, where writable entity fields can be exploited to inject malicious scripts. The vulnerability has been addressed in version 7.1.1, highlighting the importance of keeping software up to date to mitigate such security risks. For further details, visit the advisory at the provided reference.

Affected Version(s)

CRM < 7.1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.