Stored Cross-Site Scripting in ChurchCRM Management System
CVE-2026-39336
6.1MEDIUM
What is CVE-2026-39336?
ChurchCRM, an open-source church management system, contains a stored cross-site scripting vulnerability affecting various elements including the Directory Reports form fields, Person editor defaults, and external self-registration form defaults. This flaw allows an admin-to-admin stored XSS path, where writable configuration fields can be exploited. The issue has been addressed in version 7.1.0, making it essential for users to update to this release to ensure their systems are secure.
Affected Version(s)
CRM < 7.1.0
