THREAT OPS › Threat News › [GHSA] GHSA-vgp4-2fc4-qff2 (high) — Winter: Stored XSS through Editor Settings custom styles
[GHSA] GHSA-vgp4-2fc4-qff2 (high) — Winter: Stored XSS through Editor Settings custom styles
GHSA-vgp4-2fc4-qff2 Severity: high CVE: CVE-2026-32258
Winter: Stored XSS through Editor Settings custom styles
### Impact
Authenticated Backend Users with the `backend.manage_edi
Indicators of compromise
- d28f0b9474af79cfaa80eeb9d691f7a7c4469720sha1
- CVE-2026-32258cve
- CVE-2025-61674cve
Original source: https://github.com/advisories/GHSA-vgp4-2fc4-qff2