Cross-site scripting in ChurchCRM - CVE-2026-91128
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the context of users viewing affected content.
The vulnerability exists due to improper neutralization of input during web page generation in the CSV person import functionality when importing a CSV file containing crafted person or family name fields. A remote privileged user can import arbitrary HTML or script content to execute arbitrary script in the context of users viewing affected content.
User interaction is required to view content rendered in the cart listing or custom field dropdowns.