
CVE-2026-39328 ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM's person profile editing functio… https://www.cve.org/CVERecord?id=CVE-2026-39328
Post summary
The post discloses a stored XSS flaw in ChurchCRM before version 7.1.0, but offers no PoC, exploit, patch, or evidence of active exploitation.

