CVE-2026-44977: Stored XSS to Account Takeover via Feedback File Upload
A stored cross-site scripting vulnerability in Countly's feedback upload where the server trusted a client-supplied MIME type, serving attacker-controlled HTML from the application's origin and enabling full session compromise.