CVE-2026-39333 HIGH

CVE-2026-39333: ChurchCRM has Reflected XSS in DateStart/DateEnd parameters in FindFundRaiser.php

Vendor Churchcrm
Product CRM
Weakness CWE-79 · XSS
Published April 7, 2026
Last update April 7, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

Description

ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious URL that executes arbitrary JavaScript when visited by another authenticated user. This constitutes a reflected XSS vulnerability. This vulnerability is fixed in 7.1.0.

Key dates

Disclosure timeline

April 7, 2026 CVE published
April 7, 2026 Record updated