update_gallery_data of the component REST API. The manipulation of the argument arrows results in cross site scripting.This vulnerability is cataloged as CVE-2026-5361. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
SOCIAL SHARE CARD GENERATOR