THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vgp4-2fc4-qff2 (high) — Winter: Stored XSS through Editor Settings custom styles

[GHSA] GHSA-vgp4-2fc4-qff2 (high) — Winter: Stored XSS through Editor Settings custom styles

highgithub_advisoriesPublished 2026-08-12

GHSA-vgp4-2fc4-qff2 Severity: high CVE: CVE-2026-32258

Winter: Stored XSS through Editor Settings custom styles

### Impact

Authenticated Backend Users with the `backend.manage_edi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vgp4-2fc4-qff2