Low
resolved
resolved
Improper input validation in emoji field leads to sidebar UI denial of service
Bug reported by _dha was disclosed at September 20, 2026, 10:04 am | Business Logic Errors
A vulnerability was discovered in the Collectives app version 4.0.0 where the emoji field in the page emoji update endpoint did not properly validate user input. An attacker could have submitted an excessively long string including newline characters instead of a valid emoji, causing the sidebar layout to become broken.

