Cross-site scripting in ChurchCRM - CVE-2026-35574
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript code in other users' browsers.
The vulnerability exists due to cross-site scripting in NoteEditor.php when processing note content. A remote user can submit a specially crafted note to execute arbitrary JavaScript code in other users' browsers.
User interaction is required when another user views the malicious note, including on a person's profile page.