CVE-2022-36573: Pagekit

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.

Affected products

  • Pagekit Pagekit: version 1.0.18 only

Published 2022-08-29. Last modified 2026-06-17.