PT-2026-30941 · Churchcrm · Churchcrm
Saadet-T
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-35575
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 6.5.3
Description
ChurchCRM, an open-source church management system, contains a Stored Cross-Site Scripting (Stored XSS) issue in the admin panel’s group-creation feature. A user with group-creation privileges can inject malicious JavaScript that executes when an administrator views the page. This can lead to the theft of the administrator’s session cookies and potential full administrative account takeover.
Recommendations
Update to version 6.5.3 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm