Stored XSS Vulnerability in ChurchCRM by ChurchCRM
CVE-2026-39335
6.1MEDIUM
What is CVE-2026-39335?
ChurchCRM, an open-source church management system, has a Stored XSS vulnerability in the group remove control and family editor for state/country fields. This issue primarily affects admin-to-admin interactions, where writable entity fields can be exploited to inject malicious scripts. The vulnerability has been addressed in version 7.1.1, highlighting the importance of keeping software up to date to mitigate such security risks. For further details, visit the advisory at the provided reference.
Affected Version(s)
CRM < 7.1.1
