CIVI-SA-2026-23: Stored XSS in Price Field label

The price field label was not properly escaped for select price fields.

Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v6.15.2 and earlier

Fixed Versions

CiviCRM v6.15.3, v6.10.7 (ESR), and later

Publication Date
Solutions

Upgrade to a fixed version of CiviCRM

Credits

Lassi (lassitemp@proton.me), Kevin Cristiano (Tadepole Collective), Seamus Lee (JMA Consulting),