PT-2026-20912 · Churchcrm · Churchcrm
Shingleskat
·
Published
2026-02-19
·
Updated
2026-02-23
·
CVE-2026-26059
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 6.8.2
Description
ChurchCRM is an open-source church management system. An authenticated user with permission to edit groups could store a JavaScript payload that would execute when the group was viewed in the Group View. The
Group View is the affected component. Version 6.8.2 resolves this issue.Recommendations
Update to version 6.8.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Churchcrm