CVE-2026-39328Disclosure(churchcrm / churchcrm)

LOWCVSS 8.9 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch churchcrm churchcrm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Due to a 50-character field limit, the payload is distributed across all three fields and chains their onfocus event handlers to execute in sequence. When any user, including administrators, views the attacker's profile, their session cookies are exfiltrated to a remote server. This vulnerability is fixed in 7.1.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • churchcrm

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
churchcrm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 204-07
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-39328 ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functio… https://www.cve.org/CVERecord?id=CVE-2026-39328

    Post summary

    The post discloses a stored XSS flaw in ChurchCRM before version 7.1.0, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000094
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39328: HIGH] A recent vulnerability in ChurchCRM's management system allowed cross-site scripting via profile fields, exposing user sessions. Ensure ChurchCRM systems are updated to version 7.1.0.#cve,CVE-2026-39328,#cybersecurity https://cvefind.com/CVE-2026-39328

    Post summary

    The post discloses a high‑severity XSS vulnerability in ChurchCRM and urges users to update to version 7.1.0 to remediate the issue.

    0000033
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchurchcrmchurchcrm---

Explore more