UserController::ajax_blackList_post. The manipulation of the argument note leads to cross site scripting.This vulnerability is referenced as CVE-2026-39391. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR