GHSA-r82h-mqw3-fc56
CRITICALCVE-2026-55247By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.
- Affected
- < 5.2.4
- Fixed in
- 5.2.4
- Weakness
- CWE-400
- Published
- 2026-08-28
- Source
- github