GHSA-h2xq-h7f9-vh6c
HIGHCVE-2025-66024The Blog Application is vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML <title> tag without proper escaping.
- Affected
- >= 9.15, < 9.15.7
- Fixed in
- 9.15.7
- Weakness
- CWE-79
- Published
- 2026-03-04
- Source
- github