What is CVE-2026-51565?
CVE-2026-51565 is a Cross-Site Scripting (XSS) vulnerability found in the `DocsController.php` file of Milk admin versions up to 0.9.8. It allows remote attackers to inject arbitrary web script or HTML via the `action` parameter in a crafted request. Affected administrators should immediately update to the latest version or implement strict input validation.
Azərbaycanca: CVE-2026-51565, Milk admin platformasının 0.9.8 və daha əvvəlki versiyalarında `DocsController.php` faylında aşkarlanmış saxlanılan XSS (Cross-Site Scripting) zəifliyidir. Bu zəiflik `action` parametri vasitəsilə uzaqdan hücum edən şəxsə ixtiyari veb skript və ya HTML kodu yeritməyə imkan verir. Təsirə məruz qalan sistemlərin administratorları dərhal ən son versiyaya yeniləmə etməli və ya giriş validasiyası tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which file of the Milk admin platform was CVE-2026-51565 discovered?
The CVE-2026-51565 vulnerability was discovered in the `DocsController.php` file of the Milk admin platform.
Which versions of the Milk admin platform are affected by the CVE-2026-51565 stored XSS vulnerability?
Milk admin versions up to 0.9.8 are affected by this stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.