PT-2026-30948 · Churchcrm · Churchcrm

·

CVE-2026-39335

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 7.1.1
Description ChurchCRM, an open-source church management system, contains a stored cross-site scripting (XSS) issue in the group remove control and family editor state/country functionality. This primarily affects administrative users, allowing for potential abuse of writable entity fields.
Recommendations Update to version 7.1.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39335
GHSA-44J4-JJW2-WCR6

Affected Products

Churchcrm