VYPR
High severity7.2NVD Advisory· Published Jan 13, 2026· Updated Apr 15, 2026

CVE-2022-50908

CVE-2022-50908

Description

Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Mailhog/Mailhogreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = 1.0.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.