CVE-2025-65187 - CiviCRM Stored XSS

CVE-2025-65187 - CiviCRM Stored XSS

CVE ID : CVE-2025-65187 Published : Dec. 2, 2025, 4:15 p.m. | 1 hour, 51 minutes ago Description : A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Dec. 2, 2025

Source: Telegram CVE Monitor