CVE-2026-40483 | ChurchCRM up to 7.1.x Comment cross site scripting (GHSA-wjmf-w8gj-rx7g)
A vulnerability identified as problematic has been detected in ChurchCRM up to 7.1.x. This vulnerability affects unknown code. Performing a manipulation of the argument Comment results in cross site scripting.
This vulnerability is known as CVE-2026-40483. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.