{"id":"CVE-2022-25854","aliases":["GHSA-pxpf-v376-7xx5","SNYK-JS-YAIREOTAGIFY-2404358"],"url":"https://o3.security/vulnerability/CVE-2022-25854","summary":"Cross-site Scripting (XSS)","details":"This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the cross-site scripting (XSS) payload.","published":"2022-04-29T20:00:19.691Z","modified":"2026-08-12T03:51:12.766664634Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00977,"percentile":0.60477,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"@yaireo/tagify","fixedVersion":"4.9.8"}],"fix":{"url":"https://github.com/yairEO/tagify/commit/198c0451fad188390390395ccfc84ab371def4c7","label":"yairEO/tagify@198c045"},"references":[{"type":"WEB","url":"https://github.com/yairEO/tagify/releases/tag/v4.9.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25854.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25854"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-YAIREOTAGIFY-2404358"},{"type":"REPORT","url":"https://github.com/yairEO/tagify/issues/988"},{"type":"FIX","url":"https://github.com/yairEO/tagify/commit/198c0451fad188390390395ccfc84ab371def4c7"},{"type":"ARTICLE","url":"https://bsg.tech/blog/cve-2022-25854-stored-xss-in-yaireo-tagify-npm-module/"},{"type":"WEB","url":"https://bsg.tech/blog/cve-2022-25854-stored-xss-in-yaireo-tagify-npm-module"},{"type":"PACKAGE","url":"https://github.com/yairEO/tagify"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.766664634Z"}}