Released November 1, 2017
- **[Security](release-notes/4.7.26.md#security)**
+- **[Credits](release-notes/4.7.26.md#credits)**
## CiviCRM 4.7.25
Released Nov 1, 2017
- **[Security advisories](#security)**
+- **[Credits](#credits)**
## <a name="security"></a>Security advisories
- **[CIVI-SA-2017-14](https://civicrm.org/advisory/civi-sa-2017-14-xss-in-search-critiera-description)** XSS in Search Critiera Description
- **[CIVI-SA-2017-15](https://civicrm.org/advisory/civi-sa-2017-15-extension-key-not-properly-validated-when-adding-or-disabling-or)** Extension key not properly validated
- **[CIVI-SA-2017-16](https://civicrm.org/advisory/civi-sa-2017-16-sql-injection-risk-in-civireports-listing)** SQL injection risk in CiviReports
+
+## <a name="credits"></a>Credits
+
+This release was developed by the following code authors:
+
+Australian Greens - Seamus Lee; Left Join Labs - Sean Madsen
+
+Most authors also reviewed code for this release; in addition, the following
+reviewers contributed their comments:
+
+CiviCRM - Coleman Watts; JMA Consulting - Monish Deb; Wikimedia Foundation -
+Eileen McNaughton