


Perceptive Security
SOC/SIEM Consultancy

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Pr…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 19:08:14
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
ChurchCRM, an open-source church management system, contains a stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.0. The vulnerability exists in the Person Property Management subsystem and allows authenticated users to inject arbitrary JavaScript code via dynamically assigned person properties. This issue persists even in versions patched for CVE-2023-38766. The malicious payload is stored persistently and executes when other users view affected person profiles or access printable views, potentially leading to session hijacking or full account compromise. The vulnerability has been fixed in version 7.0.0.
Technical details
Mitigation steps:
Affected products:
ChurchCRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35576
https://github.com/ChurchCRM/CRM/pull/8016
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-8r36-fvxj-26qv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
