{"id":"CVE-2022-25022","title":"A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.","summary":"A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"htmly","product":"htmly","affected":["htmly = 2.8.1"],"published":"2022-03-01","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-25022","references":[{"url":"https://github.com/MoritzHuppert/CVE-2022-25022/blob/main/CVE-2022-25022.pdf","label":"cve@mitre.org"},{"url":"https://www.cvedetails.com/cve/CVE-2021-36703/","label":"cve@mitre.org"},{"url":"https://youtu.be/acookTqf3Nc","label":"cve@mitre.org"},{"url":"http://danpros.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://htmly.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/MoritzHuppert/CVE-2022-25022/blob/main/CVE-2022-25022.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cvedetails.com/cve/CVE-2021-36703/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://youtu.be/acookTqf3Nc","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01134,"epssPercentile":0.65065,"ingestedAt":"2026-07-06T02:09:23.254Z","exploits":{"github":1,"githubRepos":["https://github.com/MoritzHuppert/CVE-2022-25022"],"checkedAt":"2026-09-23T07:13:22.907Z"},"exploitAvailable":true,"slug":"CVE-2022-25022","body":"## Overview\n\nA cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.\n\n## Affected\n\n- `htmly = 2.8.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4599,"id":"CVE-2022-25022","ts":1788887193640,"field":"exploit_available","old":"false","new":"true"},{"seq":3482,"id":"CVE-2022-25022","ts":1788886310055,"field":"exploit_available","old":"true","new":"false"},{"seq":2336,"id":"CVE-2022-25022","ts":1788882979574,"field":"exploit_available","old":"false","new":"true"},{"seq":1365,"id":"CVE-2022-25022","ts":1788882392158,"field":"exploit_available","old":"true","new":"false"},{"seq":479,"id":"CVE-2022-25022","ts":1788881827783,"field":"exploit_available","old":"false","new":"true"}]}