CVE-2026-39344

ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused by the lack of sanitization or encoding of the username parameter received from the URL. The username parameter value is directly displayed in the login page input element without filter, allowing attackers to insert malicious JavaScript scripts. If successful, script can be executed on the client side, potentially stealing sensitive data such as session cookies or replacing the display to show the attacker's login form. This vulnerability is fixed in 7.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

History

09 Apr 2026, 18:42

Type Values Removed Values Added
First Time Churchcrm churchcrm
Churchcrm
CPE cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-rx8c-j7x8-w3hj - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-rx8c-j7x8-w3hj - Third Party Advisory

08 Apr 2026, 19:25

Type Values Removed Values Added
References () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-rx8c-j7x8-w3hj - () https://github.com/ChurchCRM/CRM/security/advisories/GHSA-rx8c-j7x8-w3hj -

07 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 18:16

Updated : 2026-04-09 18:42


NVD link : CVE-2026-39344

Mitre link : CVE-2026-39344

CVE.ORG link : CVE-2026-39344


JSON object : View

Products Affected

churchcrm

  • churchcrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)