Blind Reflected Cross-Site Scripting in ChurchCRM Management System
CVE-2026-39338
8.6HIGH
What is CVE-2026-39338?
ChurchCRM, an open-source church management system, is vulnerable to a Blind Reflected Cross-Site Scripting attack due to insufficient input sanitization in its dashboard search parameter. Attackers can exploit this flaw by injecting malicious script tags into API requests, which the web application's JavaScript engine executes prior to returning an HTTP 500 error. This results in unauthorized code execution within users' browsers, despite the server-side error. The issue is resolved in version 7.1.0, highlighting the importance of regular updates and rigorous security practices.
Affected Version(s)
CRM < 7.1.0
