
CVE-2026-40483 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value att… https://www.cve.org/CVERecord?id=CVE-2026-40483
Post summary
CVE-2026-40483 is a disclosed stored XSS vulnerability in ChurchCRM's Pledge Editor, with no PoC, exploit tools, active exploitation, or patch information mentioned.
