Skip to main content
Loading…
    CVE-2026-33209 — Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exists in the return_to query parameter used in the avo — CVE Database · The Intelligence Room