Cross-site scripting in ChurchCRM - CVE-2026-91128

 

Cross-site scripting in ChurchCRM - CVE-2026-91128

Published: September 29, 2026


Vulnerability identifier: #VU152740
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-91128
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the context of users viewing affected content.

The vulnerability exists due to improper neutralization of input during web page generation in the CSV person import functionality when importing a CSV file containing crafted person or family name fields. A remote privileged user can import arbitrary HTML or script content to execute arbitrary script in the context of users viewing affected content.

User interaction is required to view content rendered in the cart listing or custom field dropdowns.


Affected software

ChurchCRM

How to mitigate CVE-2026-91128

Install security update from vendor's website.

ChurchCRM - update to 7.6.1

External References

Related Security Bulletins