A vulnerability, which was classified as problematic , was found in Winter . Affected by this vulnerability is an unknown functionality of the component Editor Settings . Such manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-32258 . The attack may be performed from remote. There is no available exploit.