Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35575

27
FAUCET Score

OVERVIEW CVE-2026-35575 is a Stored Cross-Site Scripting (XSS) vulnerability affecting ChurchCRM, an open-source church management system, in versions prior to 6.5.3. The flaw exists in the admin panel's group-creation feature and allows users with group-creation privileges to inject malicious JavaScript code that executes automatically when administrators access the affected page. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.0 (HIGH) with a network-based attack vector, low attack complexity, and low privilege requirements. The primary impact is the potential theft of administrator session cookies, which could lead to complete administrative account takeover. The vulnerability requires user interaction (administrator viewing the malicious page) but poses significant confidentiality, integrity, and availability risks once exploited. EXPLOITATION STATUS Current exploitation activity is minimal. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, has an EPSS score of 0.0004 indicating very low probability of exploitation, and remains inactive on threat intelligence hot lists. No public exploit code has been widely distributed, suggesting limited community attention and active exploitation at this time. Organizations should prioritize patching to version 6.5.3 before threat actors develop functional exploits.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.5.3CPE matchmatch criteria
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.1
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 13th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / ChurchCRM/CRM/security/advisories/GHSA-gc8q-2gw7-qj7w
Third Party Advisory