CVE-2026-77166EPSS p19.0%
CVE-2026-77166CVE-2026-77166
Description
The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.
Scoring
| CVSS | 2.4 () |
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 0.28% probability of exploitation · percentile 19.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |