CVE-2026-77166

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

  • Published Sep 21, 2026
  • CVSS 2.4 low
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-77166 at the National Vulnerability Database