Cross-site scripting in ChurchCRM - CVE-2026-39333
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in the FindFundRaiser.php endpoint when handling DateStart and DateEnd parameters in HTML input attributes. A remote user can send a specially crafted link to execute arbitrary JavaScript in the victim's browser.
User interaction is required, and the victim must visit a crafted URL while having an active session.