Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
CVE-2026-97270 at the National Vulnerability Database