Loading…
CVE-2026-44990 — Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` · VulnScope