Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in ChurchCRM - #VU138416
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's authenticated session.
The vulnerability exists due to cross-site scripting in FamilyEditor.php member name fields when rendering stored family member names into HTML value attributes. A remote user can store a crafted name value to execute arbitrary JavaScript in the victim's authenticated session.
No user interaction is required once a victim opens the affected family editor page.