Cross-site scripting in ChurchCRM - CVE-2026-58411
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in request parameter handling in /FamilyCustomFieldsEditor.php, /PaddleNumList.php, and /admin/system/church-info when rendering attacker-controlled parameter names and values into JavaScript string contexts and HTML attribute contexts. A remote attacker can send a specially crafted request and trick a victim into visiting the malicious URL to execute arbitrary JavaScript in the victim's browser.
User interaction is required to visit a crafted URL.