Description
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Due to a 50-character field limit, the payload is distributed across all three fields and chains their onfocus event handlers to execute in sequence. When any user, including administrators, views the attacker's profile, their session cookies are exfiltrated to a remote server. This vulnerability is fixed in 7.1.0.
Published: 2026-04-07
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting allows session cookie exfiltration
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a stored cross‑site scripting flaw in ChurchCRM's person profile editing function. Attackers can embed malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Because each field is limited to 50 characters, the attacker distributes the payload across all three fields and chains onfocus event handlers so that the script runs in sequence when the profile is displayed. When any user, including administrators, views the attacker’s profile, the attacker’s session cookies are sent to a remote server, enabling credential theft and potential full account compromise. The weakness is an unsafe handling of user-supplied input, consistent with CWE‑79.

Affected Systems

The affected product is ChurchCRM, a free and open‑source church management system. All versions prior to 7.1.0 are vulnerable. The flaw can be triggered by any non‑administrative user who has the EditSelf permission, allowing them to inject scripts into their social profile fields.

Risk and Exploitability

The CVSS score of 8.9 indicates a high‑severity risk. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires a victim to view the malicious profile, so it relies on user interaction and can be carried out through an internal or external user who can edit their own profile. Because session cookies are delivered to an attacker‑controlled server, the impact includes potential session hijacking, data theft, and further privilege escalation within ChurchCRM.

Generated by OpenCVE AI on April 10, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to ChurchCRM version 7.1.0 or later to apply the official fix.
  • Verify that non‑administrative users cannot edit social profile fields with script content.
  • Consider implementing additional input sanitization on social profile fields to prevent XSS.

Generated by OpenCVE AI on April 10, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

Thu, 09 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Churchcrm
Churchcrm churchcrm
Vendors & Products Churchcrm
Churchcrm churchcrm

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Description ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Due to a 50-character field limit, the payload is distributed across all three fields and chains their onfocus event handlers to execute in sequence. When any user, including administrators, views the attacker's profile, their session cookies are exfiltrated to a remote server. This vulnerability is fixed in 7.1.0.
Title ChurchCRM has Stored XSS in Social Profile Fields
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Churchcrm Churchcrm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-09T15:50:07.852Z

Reserved: 2026-04-06T19:31:07.267Z

Link: CVE-2026-39328

cve-icon Vulnrichment

Updated: 2026-04-09T15:49:55.398Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-07T18:16:44.043

Modified: 2026-04-10T20:56:24.347

Link: CVE-2026-39328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T14:26:38Z

Weaknesses