
Perl CPAN CVE-2026-5090: Template::Plugin::HTML through 3.102 allows HTML and JavaScript to be injected https://www.openwall.com/lists/oss-security/2026/05/19/40
Post summary
This advisory announces CVE‑2026‑5090, a vulnerability in Perl’s Template::Plugin::HTML that enables HTML/JavaScript injection, with no PoC, exploitation evidence, or patch information provided.

