A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin interface** and is triggered when a privileged user opens the **content preview panel** of a malicious entry.
登录后查看神龙缓存的 POC 文件快照
登录查看