VYPR
Medium severity5.5NVD Advisory· Published Jan 8, 2026· Updated Apr 15, 2026

CVE-2026-22587

CVE-2026-22587

Description

Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.

Affected products

1
  • Ideagen/DevonWayllm-create
    Range: <2.62.4 and <2.62 LTS (fixed in 2.62.4 and 2.62 LTS)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.