CVE-2026-22587

Publication date

2026-01-08 17:09:03

Family

cisa-cg

State

PUBLISHED

Description

Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the Reports page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.