CVE-2022-2290
Cross-site Scripting (XSS) - Reflected in zadam/trilium
Record summary
CVE-2022-2290 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 29, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
zadam/triliumBrowse zadam / zadam/trilium | CVE List | Before 0.53.1-beta | affected |
| 0.52.4 | unaffected | ||
Nuclei templates
1ProjectDiscoveryMEDIUMTrilium <0.52.4 - Cross-Site ScriptingCVSS 6.1
Trilium prior to 0.52.4, 0.53.1-beta contains a cross-site scripting vulnerability which can allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, leading to potential data theft, session hijacking, or defacement of the affected Trilium instance.
Remediation
Upgrade Trilium to version 0.52.4 or later, which includes proper input sanitization to mitigate the XSS vulnerability.
Source: ProjectDiscovery