CVE-2026-39332
HIGHChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php
Title source: cnaDescription
ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocus with no user interaction required, an attacker can steal session cookies and fully take over any victim account, including administrator accounts, by tricking them into submitting a crafted form. This vulnerability is fixed in 7.1.0.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/ChurchCRM/CRM/security/advisories/GHSA-hc6g-h48v-wqvq
Scores
CVSS v3
8.7
EPSS
0.0020
EPSS Percentile
10.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (2)
churchcrm/churchcrm
< 7.1.0
ChurchCRM/CRM
< 7.1.0
Published
Apr 07, 2026
Tracked Since
Apr 07, 2026