Medium severity4.8NVD Advisory· Published Nov 29, 2022· Updated Jun 17, 2026
CVE-2022-36137
CVE-2022-36137
Description
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- grimthereaperteam.medium.com/churchcrm-version-4-4-5-stored-xss-vulnerability-at-sheader-2ed4184030f7nvdExploitThird Party Advisory
- github.com/ChurchCRM/CRM/releases/tag/4.4.5nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.