Blind Reflected Cross-Site Scripting in ChurchCRM Management System
CVE-2026-39338

8.6HIGH

Key Information:

Vendor

Churchcrm

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39338?

ChurchCRM, an open-source church management system, is vulnerable to a Blind Reflected Cross-Site Scripting attack due to insufficient input sanitization in its dashboard search parameter. Attackers can exploit this flaw by injecting malicious script tags into API requests, which the web application's JavaScript engine executes prior to returning an HTTP 500 error. This results in unauthorized code execution within users' browsers, despite the server-side error. The issue is resolved in version 7.1.0, highlighting the importance of regular updates and rigorous security practices.

Affected Version(s)

CRM < 7.1.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.