Medium severity5.4NVD Advisory· Published Jul 28, 2022· Updated Jun 17, 2026
CVE-2022-34140
CVE-2022-34140
Description
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
feehi/cmsPackagist | <= 2.1.1 | — |
Affected products
3- Feehi/CMSdescription
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/168012/Feehi-CMS-2.1.1-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/168476/Feehi-CMS-2.1.1-Remote-Code-Execution.htmlnvdExploitThird Party Advisory
- github.com/liufee/cms/issues/61nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-25q6-m425-9fqrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-34140ghsaADVISORY
News mentions
0No linked articles in our index yet.