216.73.216.197

CVE-2026-22587

· Published 08/01/2026 18:16 · Modified 08/01/2026 18:16

Labels: CVE-2026-22587 2026-01-089119a7d8-5eab-497f-8521-727c672e3725CVE-2026-22587CWE-79

Essential information

Published
08/01/2026 18:16
Modified
08/01/2026 18:16
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
ideagen / devonway cpe:2.3:a:ideagen:devonway:2.62.4:*:*:*:*:*:*:*
ideagen / devonway cpe:2.3:a:ideagen:devonway:2.62:*:*:*:*:*:*:*

References