
CVE-2026-40593 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML inpu… https://www.cve.org/CVERecord?id=CVE-2026-40593
Post summary
The tweet references CVE‑2026‑40593, a vulnerability in ChurchCRM where usernames are unsanitized when rendered into an HTML input. No proof of concept, exploit, active exploitation, or patch information is provided.
