Product
The Sakai Conversations tool suffers from a stored cross-site scripting (XSS) vulnerability, CVE-2026-54049, allowing authenticated users to execute arbitrary JavaScript in the browsers of other site members.