CVE-2026-40593
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking characters and event handlers, which execute in the browser of any administrator who subsequently views that user's editor page, resulting in stored XSS.
This issue has been fixed in version 7.2.0.
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N- 18 Apr 2026Published to NVD
- 20 Apr 2026Last modified
ATT&CK techniques
2Techniques this CVE enables - linked via CWE → CAPEC → ATT&CK. Pills with a solid outline are named directly in ATT&CK or Nuclei templates (high confidence); the others are linked through weakness mappings.
▤ Build a SIEM detection for these techniquesCAPEC attack patterns
9Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.