Cross-site scripting in ChurchCRM - #VU138419
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in person/family record views when rendering a person's name into an HTML attribute. A remote user can supply a crafted person name containing a JavaScript event handler to execute arbitrary script code in a victim's browser.
An anonymous user can exploit this issue if self-registration is enabled, and user interaction is required when a staff member or administrator views the affected person or family record.