9.9.1-alpha.4 (2026-06-01) Bug Fixes Stored XSS via trailing-dot filename bypassing file upload extension blocklist (GHSA-7wqv-xjf3-x35v) (#10489) (66484ce)