#VU125711 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2026-39336
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser session.
The vulnerability exists due to cross-site scripting in multiple ChurchCRM pages when rendering persisted configuration values inside HTML attribute contexts without attribute-safe encoding. A remote privileged user can store a specially crafted configuration value to execute arbitrary script in a victim's browser session.
User interaction is required, and exploitation occurs when another user visits an affected page that renders the stored value.