SB2026092925 - Multiple vulnerabilities in ChurchCRM



SB2026092925 - Multiple vulnerabilities in ChurchCRM

Published: September 29, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092925
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2026-91128)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in the context of users viewing affected content.

The vulnerability exists due to improper neutralization of input during web page generation in the CSV person import functionality when importing a CSV file containing crafted person or family name fields. A remote privileged user can import arbitrary HTML or script content to execute arbitrary script in the context of users viewing affected content.

User interaction is required to view content rendered in the cart listing or custom field dropdowns.


2) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete a church calendar.

The vulnerability exists due to missing authorization in the DELETE /api/calendars/{id} endpoint when handling authenticated DELETE requests. A remote user can send a DELETE request for a calendar identifier to delete a church calendar.

Deleting a shared calendar also removes its associated access token.


3) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose events from other calendars, including private calendars.

The vulnerability exists due to improper authorization in PublicCalendarMiddleware::getEvents() when handling public calendar requests containing a start parameter. A remote user can send a request containing a start parameter to disclose events from other calendars, including private calendars.

The external calendar API must be enabled, and a public calendar access token must be available.


Remediation

Install update from vendor's website.