CVE-2026-24855Disclosure(churchcrm / churchcrm)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch churchcrm churchcrm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and when other users view that event (including the admin), the payload is triggered, leading to account takeover. Version 6.7.2 fixes the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-30: 2Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-30: 201-30
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24855 Stored XSS Vulnerability in ChurchCRM Church Calendar Prior to 6.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24855 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-24855, a stored XSS flaw in ChurchCRM Church Calendar before version 6, without providing any proof of concept, exploitation tool, patch, or evidence of active exploitation.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-24855 ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church… https://www.cve.org/CVERecord?id=CVE-2026-24855

    Post summary

    CVE-2026-24855 is a stored XSS flaw in ChurchCRM before version 6.7.2; updating to 6.7.2 or later resolves the issue.

    00000156
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more