


Perceptive Security
SOC/SIEM Consultancy

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authen…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 18:06:01
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
ChurchCRM, an open-source church management system, contains a stored Cross-Site Scripting (XSS) vulnerability in its Note Editor component prior to version 6.5.3. The vulnerability allows authenticated users with note-adding permissions to execute arbitrary JavaScript code in other users' browsers, including administrators. This can result in session hijacking, privilege escalation, and unauthorized access to sensitive church member data. The issue has been resolved in version 6.5.3.
Technical details
Mitigation steps:
Affected products:
ChurchCRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35574
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-cx82-8xrh-7f5c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
