CVE-2023-6710: stored XSS in mod_cluster-manager HTML output via virtual host
and context names rendered without HTML escaping
CVE-2024-10306: unauthorized MCMP requests due to <Directory> directive being
ignored for protocol-handler filtering; runtime guard now refuses <Directory>
siblings of EnableMCPMReceive, and the shipped conf.sample uses <Location>