Critical severity9.0NVD Advisory· Published Nov 25, 2022· Updated Jul 9, 2026
CVE-2022-37721
CVE-2022-37721
Description
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyrocms/pyrocmsPackagist | <= 3.9.1 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-cm7f-hf2g-ghrpghsaADVISORY
- labs.integrity.pt/advisories/cve-2022-37721/nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2022-37721ghsaADVISORY
- labs.integrity.pt/advisories/cve-2022-37721ghsaWEB
News mentions
0No linked articles in our index yet.