
CVE-2026-35575 ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation fea… https://www.cve.org/CVERecord?id=CVE-2026-35575
Post summary
The text reports a stored XSS vulnerability in ChurchCRM’s admin panel group‑creation feature affecting versions before 6.5.3.
