
CVE-2026-39332 ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerability in GeoPage.php allows any authenticated use… https://www.cve.org/CVERecord?id=CVE-2026-39332
Post summary
The post announces a reflected XSS vulnerability in ChurchCRM’s GeoPage.php for versions below 7.1.0, with no mention of PoCs, exploits, patches, or active exploitation in the wild.

