Stored Cross-Site Scripting in ChurchCRM Management System
CVE-2026-39336

6.1MEDIUM

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39336?

ChurchCRM, an open-source church management system, contains a stored cross-site scripting vulnerability affecting various elements including the Directory Reports form fields, Person editor defaults, and external self-registration form defaults. This flaw allows an admin-to-admin stored XSS path, where writable configuration fields can be exploited. The issue has been addressed in version 7.1.0, making it essential for users to update to this release to ensure their systems are secure.

Affected Version(s)

CRM < 7.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.