CVE list

by @udontknow.us

[unofficial] Collect posts with a reference to CVEs

Pull to refresh
The Standup @standup.thecompound.tech · 10h
1

CVE-2026-107845 lets unauthenticated Contao Comments Bundle visitors inject JavaScript into the back end. Opening the Comments module executes it in the user's session; the back end sends no CSP.