CVE-2022-1345: Organizr
Critical severity, CVSS 9.0. EPSS: 1% chance of exploitation in the next 30 days.
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
Affected products
- Organizr Organizr: before 2.1.1810 (fixed in 2.1.1810)
Published 2022-04-13. Last modified 2026-06-17.