CVE-2026-39333 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: April 7, 2026
ChurchCRM - Reflected XSS
Published: April 7, 2026Updated: April 7, 2026Remote Exploitable
Overview
ChurchCRM < 7.1.0 contains a reflected XSS caused by improper output encoding of DateStart and DateEnd parameters in FindFundRaiser.php, letting authenticated attackers execute arbitrary JavaScript via crafted URLs.
Severity & Score
Severity: High
CVSS Score: 8.7
Impact
Authenticated attackers can execute arbitrary JavaScript in other users' browsers, potentially stealing session data or performing actions on their behalf.
Mitigation
Update to version 7.1.0 or later.
Related Resources
Details
- CVE ID
- CVE-2026-39333
- Severity
- High
- CVSS Score
- 8.7
- Type
- reflected_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N