CIVI-SA-2026-08: Custom Data Settings (XSS)

Published
2026-03-18 12:00
Written by
Security Risk
Moderately Critical
Vulnerability
Cross Site Scripting
Affected Versions

CiviCRM v6.12.0 and earlier

Fixed Versions

CiviCRM v6.12.1, v6.10.3 (ESR), and later

Publication Date
Solutions

Upgrade to a fixed version of CiviCRM.

Credits

John Kingsnorth, Lassi (lassitemp@proton.me), Seamus Lee (JMA Consulting), Luke Stewart (Fuzion), Coleman Watts (CiviCRM)