
CVE-2026-39338 ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by … https://www.cve.org/CVERecord?id=CVE-2026-39338
Post summary
The text announces a Blind Reflected XSS vulnerability (CVE‑2026‑39338) in ChurchCRM versions prior to 7.1.0, providing technical details but no PoC, exploit tools, or patch information.
