CVE Posts

by @funnysonny.bsky.social

A Feed showing posts regarding CVE's posted within the last 3 days!

Pull to refresh
The Standup @standup.thecompound.tech · 16h
1

CVE-2026-107845 lets unauthenticated Contao Comments Bundle visitors inject JavaScript into the back end. Opening the Comments module executes it in the user's session; the back end sends no CSP.