CIVI-SA-2026-20: Stored XSS in Website URL
When viewing a contact in the contact summary screen, the contact's website URL was not properly escaped.
When viewing a contact in the contact summary screen, the contact's website URL was not properly escaped.
When viewing a grant or printing a list of grants the Grant type label and Grant Status labels were not properly escaped
When viewing.a scheduled job the job name was not properly escaped when displayed
Want to help improve multisite by making your reports clear between domains?
Right now, your contacts are segmented by domain within a shared multisite network setup, but if any of those constituents are shared between domains, both domains see all contributions, whether or not those contributions belong to your domain organization. That makes reporting look muddled. This is particularly a problem on the contribution dashboard but also applies to participants and member reports.
CiviCRM has great built-in tools for site builders and power users. SearchKit and FormBuilder's many options allow sophisticated users to create wonderful ad hoc queries and complex forms quickly.
But for nonprofit staff, including those who use CiviCRM occasionally, they can be complicated and challenging. Or worse: too confusing, too hard.
We want to change that.
Thanks to the hard work of CiviCRM’s incredible community of contributors, CiviCRM version 6.15.0 is now ready to download. This is a regular monthly release that includes new features and bug fixes. Details are available in the monthly release notes.
Your are encouraged to upgrade now for the most stable, secure CiviCRM experience:
On May 20–27, 2026, Symfony published 36 security advisories alongside security releases for Symfony 5.4.52, 6.4.40, 7.4.12, 8.0.12, and Twig 3.26.0. The CiviCRM security team has reviewed these advisories and assessed their impact on CiviCRM. The security team has determined that these advisories have low to no impact on CiviCRM.
Thanks to the hard work of CiviCRM’s incredible community of contributors, CiviCRM version 6.13.0 is now ready to download. This is a regular monthly release that includes new features and bug fixes. Details are available in the monthly release notes.
Your are encouraged to upgrade now for the most stable, secure CiviCRM experience:
For organizations which use custom data with an access control list (ACL) , backend users may use "Advanced Search" to discover implicit information from restricted fields.