Medium severity5.4NVD Advisory· Published Jun 9, 2022· Updated Jun 17, 2026
CVE-2022-2015
CVE-2022-2015
Description
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- jgraph/jgraph/drawiov5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/jgraph/drawio/commit/3d3f819d7a04da7d53b37cc0ca4269c157ba2825nvdPatchThird Party Advisory
- huntr.dev/bounties/0d32f448-155c-4b71-9291-9e8bcd522b37nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.