CVE-2026-22587: Ideagen Devonway

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a payload in the 'Reports' page that executes when another user views the report. Fixed in 2.62.4 and 2.62 LTS.

Affected products

  • Ideagen Devonway: before 2.62.4 (fixed in 2.62.4)

Published 2026-01-08. Last modified 2026-06-17.