Home

Description

ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and when other users view that event (including the admin), the payload is triggered, leading to account takeover. Version 6.7.2 fixes the vulnerability.

PUBLISHED Reserved 2026-01-27 | Published 2026-01-30 | Updated 2026-01-30 | Assigner GitHub_M




HIGH: 7.2CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:P

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 6.7.2
affected

References

github.com/...RM/CRM/security/advisories/GHSA-49qp-cfqx-c767

github.com/...ommit/0cd0d211459b8c19509d36b3c1dfcd7f8c10d914

github.com/...ommit/ec4b16e9a3ca09c8a01a712bcb90579c42f2ba28

cve.org (CVE-2026-24855)

nvd.nist.gov (CVE-2026-24855)

Download JSON