Vulnerability Description
ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request parameter names and parameter values. The application reflects attacker-controlled input into JavaScript string contexts and HTML attribute contexts without proper sanitization or contextual output encoding. Affected endpoints observed during testing: /FamilyCustomFieldsEditor.php, /PaddleNumList.php and /admin/system/church-info. Potential consequences include session-token theft, account takeover, unauthorized actions on behalf of authenticated users, exposure of sensitive church member information, credential harvesting, phishing, and privilege escalation when administrators are targeted. This issue has been resolved in version 7.4.0.
Related Weaknesses (CWE)
References
- https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p6j6-vrpg-4pp8
- https://github.com/ChurchCRM/CRM/security/advisories/GHSA-p6j6-vrpg-4pp8
FAQ
What is CVE-2026-58411?
CVE-2026-58411 is a documented vulnerability. ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insufficient output encoding of user-controlled request ...
How severe is CVE-2026-58411?
CVSS scoring is not yet available for CVE-2026-58411. Check NVD for updates.
Is there a patch for CVE-2026-58411?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.