CIVI-SA-2026-05: APIv3 Explorer (XSS)

Published
2026-03-18 12:00
Written by
Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v6.12.0 and earlier

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later

Publication Date
Solutions
  • Upgrade to a fixed version of CiviCRM
Credits

Lassi (lassitemp@proton.me), Coleman Watts (CiviCRM), Seamus Lee (JMA Consulting)