Description

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permissions can inject HTML attribute-breaking characters and event handlers into the comment field, which are stored in the database and execute in the browser of any user who subsequently opens the pledge record for editing, resulting in stored XSS. This issue has been fixed in version 7.2.0.

INFO

Published Date :

2026-04-17T23:20:44.900Z

Last Modified :

2026-04-20T16:16:17.841Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-40483 vulnerability.

Vendors Products
Churchcrm
  • Churchcrm

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact