Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated user to inject arbitrary JavaScript into the browser of another authenticated user. Because the payload fires automatically via autofocus with no user interaction required, an attacker can steal session cookies and fully take over any victim account, including administrator accounts, by tricking them into submitting a crafted form. This vulnerability is fixed in 7.1.0. | |
| Title | ChurchCRM has Reflected Cross-Site Scripting (XSS) in GeoPage.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T14:41:01.071Z
Reserved: 2026-04-06T20:28:38.393Z
Link: CVE-2026-39332
Updated: 2026-04-08T14:40:56.523Z
Status : Awaiting Analysis
Published: 2026-04-07T18:16:44.717
Modified: 2026-04-08T21:27:00.663
Link: CVE-2026-39332
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:47:05Z