
CVE-2026-35534 ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of san… https://www.cve.org/CVERecord?id=CVE-2026-35534
Post summary
The tweet announces a stored XSS flaw in ChurchCRM (before version 7.1.0) with basic technical details, but does not provide exploit code, patch info, or evidence of active exploitation.

