
CVE-2026-39344 ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vulnerability on the login page, which is caused… https://www.cve.org/CVERecord?id=CVE-2026-39344
Post summary
The text announces the discovery of a reflected XSS flaw in ChurchCRM (CVE‑2026‑39344) affecting versions prior to 7.1.0, without providing PoC, exploit, or patch details.
