CVE-2026-39332

HIGH

ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php

Title source: cna
STIX 2.1

Description

ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocus with no user interaction required, an attacker can steal session cookies and fully take over any victim account, including administrator accounts, by tricking them into submitting a crafted form. This vulnerability is fixed in 7.1.0.

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
churchcrm/churchcrm < 7.1.0
ChurchCRM/CRM < 7.1.0
Published Apr 07, 2026
Tracked Since Apr 07, 2026