{"id":"CVE-2022-23059","aliases":["GHSA-p2j7-6g9h-32xh"],"url":"https://o3.security/vulnerability/CVE-2022-23059","summary":"Shopizer - Stored XSS in Manage Images","details":"A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images” tab, which allows an attacker to upload a SVG file containing malicious JavaScript code.","published":"2022-03-29T10:25:09.479Z","modified":"2026-08-08T03:47:27.816695912Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.shopizer:shopizer","fixedVersion":"3.0.0"}],"fix":{"url":"https://github.com/shopizer-ecommerce/shopizer/commit/6b9f1ecd303b3b724d96bd08095c1a751dcc287e","label":"shopizer-ecommerce/shopizer@6b9f1ec"},"references":[{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23059"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23059.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23059"},{"type":"FIX","url":"https://github.com/shopizer-ecommerce/shopizer/commit/6b9f1ecd303b3b724d96bd08095c1a751dcc287e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:27.816695912Z"}}