LOWVulnerability
CVE-2026-82838
The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.
Properties
- epss_score
- 0.00234
- cve_id
- CVE-2026-82838
- published_at
- 2026-08-31T08:17:04.080
- last_modified
- 2026-09-03T18:12:56.407
- epss_percentile
- 0.14216
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph