
Security Advisory for CVE-2026-51565
Security Advisory for CVE-2026-51565
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request
At the time of publication, no official patch is available from the creator for this vulnerability and it's been 5 months I reported this. Until an updated version is released, it is recommended to deploy a Web Application Firewall (WAF) such as ModSecurity configured with appropriate xss protection rules to help block malicious requests targeting the vulnerable action parameter. Administrators should also consider restricting access to the affected functionality where possible and monitor application logs for suspicious requests. These measures are intended as temporary mitigations and should not be considered a replacement for an official security update. Once a patched version becomes available then administrators should upgrade as soon as possible.