#VU125709 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2026-39335
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser session.
The vulnerability exists due to cross-site scripting in group and family controls when rendering persisted values inside HTML data-* attributes without attribute-safe escaping. A remote privileged user can store a specially crafted value that breaks out of an attribute and injects executable event handlers to execute arbitrary script in a victim's browser session.
User interaction is required to load the affected page or trigger the vulnerable control.