PT-2026-30941 · Churchcrm · Churchcrm

Saadet-T

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35575

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a Stored Cross-Site Scripting (Stored XSS) issue in the admin panel’s group-creation feature. A user with group-creation privileges can inject malicious JavaScript that executes when an administrator views the page. This can lead to the theft of the administrator’s session cookies and potential full administrative account takeover.
Recommendations Update to version 6.5.3 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35575

Affected Products

Churchcrm