Medium severity4.8NVD Advisory· Published Nov 29, 2022· Updated Jun 17, 2026
CVE-2022-36136
CVE-2022-36136
Description
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- grimthereaperteam.medium.com/churchcrm-version-4-4-5-stored-xss-vulnerability-at-deposit-commend-839d2c587d6envdExploitThird Party Advisory
- github.com/ChurchCRM/CRM/releases/tag/4.4.5nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.