
CVE-2026-39335 ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and family editor state/country. This is primarily a… https://www.cve.org/CVERecord?id=CVE-2026-39335
Post summary
The post announces a new stored XSS vulnerability (CVE‑2026‑39335) in ChurchCRM, detailing affected components but provides no exploit, patch, or PoC information.
