CVE detail
CVE-2026-22919
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Vendor Advisorywww.sick.comJan 15, 2026, 1:16 PMNo excerpt available.
Vendor Advisorywww.sick.comJan 15, 2026, 1:16 PMNo excerpt available.
Vendor Advisorywww.sick.comJan 15, 2026, 1:16 PM- https://www.first.org/cvss/calculator/3.1www.first.org
No excerpt available.
Not Applicablewww.first.orgJan 15, 2026, 1:16 PM No excerpt available.
Mitigationwww.cisa.govJan 15, 2026, 1:16 PM- https://sick.com/psirtsick.com
No excerpt available.
Vendor Advisorysick.comJan 15, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-22913CVSS 4.3 · Medium
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.
- CVE-2026-22918CVSS 4.3 · Medium
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extracti…
- CVE-2026-22917CVSS 4.3 · Medium
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
- CVE-2026-22916CVSS 4.3 · Medium
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disrup…
- CVE-2026-22915CVSS 4.3 · Medium
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.
- CVE-2026-22914CVSS 4.3 · Medium
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.