
CVE-2026-39941 ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and EDesc parameters in… https://www.cve.org/CVERecord?id=CVE-2026-39941
Post summary
The passage describes an XSS flaw in ChurchCRM versions older than 7.1.0 that can be triggered via the EName and EDesc fields, but provides no PoC, patch, or exploitation evidence.

