ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue. | |
| Title | ChurchCRM has Stored Cross-Site Scripting (XSS) in GroupEditor.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-19T18:45:53.171Z
Reserved: 2026-02-10T18:01:31.899Z
Link: CVE-2026-26059
No data.
Status : Received
Published: 2026-02-19T19:22:29.693
Modified: 2026-02-19T19:22:29.693
Link: CVE-2026-26059
No data.
OpenCVE Enrichment
No data.