#VU125699 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2026-35534
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in PersonView.php when rendering the Facebook field in an HTML attribute context. A remote user can store a specially crafted Facebook field value to execute arbitrary JavaScript in a victim's browser.
User interaction is required when a victim views the affected person's profile page.