CIVI-SA-2026-07: Contact Summary (XSS)

Publié
2026-03-18 12:00
Written by
Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v6.12.0 and earlier

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later

Publication Date
Solutions

Any ONE of the following will mitigate the vulnerability:

  • Upgrade to a fixed version of CiviCRM
Credits

Luke Stewart (Fuzion), Lassi (lassitemp@proton.me), Seamus Lee (JMA Consulting), Kevin Cristiano (Tadpole Collective)