{"id":"CVE-2022-47419","aliases":["GHSA-5m6v-2xgf-qhrw","PYSEC-2023-276"],"url":"https://o3.security/vulnerability/CVE-2022-47419","summary":"Mayan EDMS Tag XSS","details":"An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system.","published":"2023-02-07T21:47:48.772Z","modified":"2026-08-12T03:51:14.586689407Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00536,"percentile":0.42875,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"mayan-edms","fixedVersion":"4.3.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/47xxx/CVE-2022-47419.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-47419"},{"type":"ADVISORY","url":"https://www.mayan-edms.com/news/2023/02/version-4.3.6/"},{"type":"ADVISORY","url":"https://www.rapid7.com/blog/post/2023/02/07/multiple-dms-xss-cve-2022-47412-through-cve-20222-47419/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.586689407Z"}}