Description
Vanilla before 2.6.1 allows XSS via the email field of a profile.
Remediation
References
Related Vulnerabilities
Craft CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-14280)
WordPress Plugin Fuctweb CapCC 'plugins.php' SQL Injection (1.0)
WordPress Plugin WordPress Access Areas Security Bypass (1.3.0)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7890)