Cross-site scripting in ChurchCRM - CVE-2025-68275
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the group name field when rendering person listing pages. A remote privileged user can create a group with a specially crafted name to execute arbitrary script in a victim's browser.
User interaction is required to view the affected people listing pages.