CIVI-SA-2026-06: Contact Notes (XSS)

Gepubliceerd
2026-03-18 12:00
Written by
Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v6.12.0 and earlier

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later

Publication Date
Solutions

Any ONE of the following will mitigate the vulnerability:

  • Upgrade to a fixed version of CiviCRM
Credits

Lassi (lassitemp@proton.me), Seamus Lee (JMA Consulting), Luke Stewart (Fuzion), Coleman Watts (CiviCRM),