SB2026092925 - Multiple vulnerabilities in ChurchCRM
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2026-91128)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the context of users viewing affected content.
The vulnerability exists due to improper neutralization of input during web page generation in the CSV person import functionality when importing a CSV file containing crafted person or family name fields. A remote privileged user can import arbitrary HTML or script content to execute arbitrary script in the context of users viewing affected content.
User interaction is required to view content rendered in the cart listing or custom field dropdowns.
2) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete a church calendar.
The vulnerability exists due to missing authorization in the DELETE /api/calendars/{id} endpoint when handling authenticated DELETE requests. A remote user can send a DELETE request for a calendar identifier to delete a church calendar.
Deleting a shared calendar also removes its associated access token.
3) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose events from other calendars, including private calendars.
The vulnerability exists due to improper authorization in PublicCalendarMiddleware::getEvents() when handling public calendar requests containing a start parameter. A remote user can send a request containing a start parameter to disclose events from other calendars, including private calendars.
The external calendar API must be enabled, and a public calendar access token must be available.
Remediation
Install update from vendor's website.