
CVE-2026-39336 ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Directory Reports form fields set from config, P… https://www.cve.org/CVERecord?id=CVE-2026-39336
Post summary
The post announces CVE‑2026‑39336 as a stored XSS flaw in ChurchCRM before version 7.1.0 affecting Directory Reports form fields.
