
CVE-2026-32880 ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type system settings to store a JavaScript payload that… https://www.cve.org/CVERecord?id=CVE-2026-32880
Post summary
The brief description discloses that CVE-2026-32880 allows privileged administrators in ChurchCRM pre‑7.0.2 to inject JavaScript via JSON system settings; no PoC, exploit code, active exploitation, or patch information is provided.
