CVE-2026-39335: Churchcrm

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily an admin-to-admin stored XSS path when writable entity fields are abused. This vulnerability is fixed in 7.1.1.

Affected products

  • Churchcrm Churchcrm: up to and including 7.1.1

Published 2026-04-07. Last modified 2026-06-17.