#VU125716 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ChurchCRM - CVE-2025-68399
Published: April 9, 2026
ChurchCRM
ChurchCRM
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in GroupEditor.php when creating a group role. A remote user can submit a crafted role value to execute arbitrary JavaScript in a victim's browser.
Exploitation requires permission to view and modify groups, and the payload is stored and executed when a user visits the vulnerable page.