VYPR
Medium severity5.4NVD Advisory· Published Feb 19, 2026· Updated Jun 17, 2026

CVE-2026-26059

CVE-2026-26059

Description

ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated user with permission to edit groups to store a JavaScript payload that would execute when the group was viewed in the Group View. Version 6.8.2 fixes this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*range: <6.8.2
    • (no CPE)range: <6.8.2
  • Range: < 6.8.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.