PT-2026-5408 · Churchcrm · Churchcrm

Sonntb21Dcat164

·

Published

2026-01-30

·

Updated

2026-02-17

·

CVE-2026-24855

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.7.2
Description ChurchCRM, an open-source church management system, contains a Stored Cross-Site Scripting (XSS) issue in the Create Events feature within the Church Calendar. A user with limited privileges can inject malicious code into the Description field. This code is then saved to the database and executed when other users, including administrators, view the event. This can lead to account compromise.
Recommendations Update to ChurchCRM version 6.7.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24855
GHSA-49QP-CFQX-C767

Affected Products

Churchcrm