CVE-2026-26059 | ChurchCRM up to 6.8.0 Group View cross site scripting (GHSA-3wp4-vpr7-47q6)
A vulnerability described as problematic has been identified in ChurchCRM up to 6.8.0. This impacts an unknown function of the component Group View. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-26059. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.