CVE-2022-40434
Critical · CVSS 9.8Softr — HTML Injection (Stored XSS)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-79, CWE-79
Description
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
Search profile — drives PoC discovery
Symbols Name fieldAccount pageHTML injectionsoftr.io
Keywords CVE-2022-40434Softr v2.0HTML injectionName fieldAccount pageXSSSoftr vulnerabilitystored HTML injection
Versions: v2.0
References
- https://isaghojaria.medium.com/softr-v2-0-was-discovered-to-be-vulnerable-to-html-injection-via-the-name-field-of-the-account-page-c6fbd3162254
- https://www.softr.io/
- http://softr.com
- https://isaghojaria.medium.com/softr-v2-0-was-discovered-to-be-vulnerable-to-html-injection-via-the-name-field-of-the-account-page-c6fbd3162254
- https://www.softr.io/
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z