#VU125689 Cross-site scripting in ChurchCRM - CVE-2026-26059
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in GroupEditor.php when processing group role name updates. A remote user can store a specially crafted JavaScript payload to execute arbitrary JavaScript in a victim's browser.
The payload executes when the group is viewed in the group viewer.