CVE-2026-35574 Details
Description
ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authenticated users with note-adding permissions to execute arbitrary JavaScript code in the context of other users' browsers, including administrators. This can lead to session hijacking, privilege escalation, and unauthorized access to sensitive church member data. This vulnerability is fixed in 6.5.3.
A stored Cross-Site Scripting (XSS) vulnerability has been identified in ChurchCRM, an open-source church management system, prior to version 6.5.3. This vulnerability allows authenticated users with permission to add notes to execute arbitrary JavaScript in the context of other users' browsers, including administrators. The issue arises because the Note Editor does not properly sanitize user input before storing it, enabling the execution of malicious scripts when the notes are viewed. The vulnerability could lead to session hijacking, privilege escalation, and unauthorized access to sensitive church member data.
Users should update to ChurchCRM version 6.5.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-cx82-8xrh-7f5c | CISA-ADP | ExploitVendor Advisory |
| https://github.com/ChurchCRM/CRM/security/advisories/GHSA-cx82-8xrh-7f5c | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| churchcrm churchcrm | < 6.5.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | New CVE Received | [email protected] |