OVERVIEW CVE-2026-35575 is a Stored Cross-Site Scripting (XSS) vulnerability affecting ChurchCRM, an open-source church management system, in versions prior to 6.5.3. The flaw exists in the admin panel's group-creation feature and allows users with group-creation privileges to inject malicious JavaScript code that executes automatically when administrators access the affected page. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.0 (HIGH) with a network-based attack vector, low attack complexity, and low privilege requirements. The primary impact is the potential theft of administrator session cookies, which could lead to complete administrative account takeover. The vulnerability requires user interaction (administrator viewing the malicious page) but poses significant confidentiality, integrity, and availability risks once exploited. EXPLOITATION STATUS Current exploitation activity is minimal. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, has an EPSS score of 0.0004 indicating very low probability of exploitation, and remains inactive on threat intelligence hot lists. No public exploit code has been widely distributed, suggesting limited community attention and active exploitation at this time. Organizations should prioritize patching to version 6.5.3 before threat actors develop functional exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.3CPE matchmatch criteria | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.