ShowDoc prior to 2.10.4 is vulnerable to stored cross-site scripting via file upload. References https://nvd.nist.gov/vuln/detail/CVE-2022-0966 https://github.com/star7th/showdoc/commit/3caa32334db0c277b84e993eaca2036f5d1dbef8 https://huntr.dev/bounties/e06c0d55-00a3-4f82-a009-0310b2e402fe https://github.com/advisories/GHSA-g585-j55v-38h7