CVE-2026-22707 — Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type re — CVE Database · The Intelligence Room