Stored Cross Site Scripting Vulnerability in CiviCRM by CiviCRM LLC
CVE-2025-65187

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 December 2025

What is CVE-2025-65187?

A Stored Cross Site Scripting vulnerability is present in the Accounting Batches field of CiviCRM prior to version 6.7. Authenticated users can exploit this vulnerability by injecting malicious JavaScript, which executes upon viewing the affected page. This can lead to unauthorized actions or exposure of sensitive information, emphasizing the importance of timely updates and security measures.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.