{"id":"CVE-2022-4105","aliases":["GHSA-hf94-8mx5-2vvj","PYSEC-2026-837"],"url":"https://o3.security/vulnerability/CVE-2022-4105","summary":"Cross-site Scripting (XSS) - Stored in kiwitcms/kiwi","details":"A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.","published":"2022-11-21T00:00:00Z","modified":"2026-07-15T01:48:56.399966995Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"kiwitcms","fixedVersion":"11.6"}],"fix":{"url":"https://github.com/kiwitcms/kiwi/commit/a2b169ffdef1d7c1755bade8138578423b35011b","label":"kiwitcms/kiwi@a2b169f"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/386417e9-0cd5-4d80-8137-b0fd5c30b8f8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4105.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4105"},{"type":"FIX","url":"https://github.com/kiwitcms/kiwi/commit/a2b169ffdef1d7c1755bade8138578423b35011b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:56.399966995Z"}}