PT-2026-30920 · Churchcrm · Churchcrm

Uartu0

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35574

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a stored Cross-Site Scripting (XSS) flaw in the Note Editor. Authenticated users with note-adding permissions can execute arbitrary JavaScript code in the context of other users’ browsers, including administrators. This could lead to session hijacking, privilege escalation, and unauthorized access to sensitive church member data.
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-35574

Affected Products

Churchcrm