CVEs affecting projects tracked on Release Alert, from NVD & OSV.
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.