Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2026-35576

 

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2026-35576

Published: April 9, 2026


Vulnerability identifier: #VU125693
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-35576
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the context of other users.

The vulnerability exists due to cross-site scripting in the Person Property Management subsystem when processing dynamically assigned property values. A remote user can submit a specially crafted property value to execute arbitrary JavaScript in the context of other users.

User interaction is required when another user views the affected person profile or accesses the printable view.


Affected software

ChurchCRM

How to mitigate CVE-2026-35576

Install security update from vendor's website.

ChurchCRM - update to 7.0.0

External References

Related Security Bulletins