CVE-2022-50965
📛 CVE Title
(no title)
Description
uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.1 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N- Effective score
- 6.1 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2022-50965
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-10 13:16:34 UTC
- NVD last modified
- 2026-05-12 14:24:15 UTC
- NVD CVSS v3.1
- 6.1 / 10 MEDIUM source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 2.7 / 10
- EPSS score
- 0.0004 (probability of exploitation in next 30 days)
- EPSS percentile
- 12.77% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-79
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-24 23:54 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2022-55986 - Assigner
- VulnCheck
- Published
- May 10, 2026, 12:12:58 PM
- Updated
- May 24, 2026, 1:37:32 AM
- EUVD base score (CVSS 4.0)
-
5.1 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N - EUVD-reported EPSS
- 0.0400
- Vendors
- uBidAuction
- Products
-
uBidAuction (2.0.1)
ENISA description: uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the posts/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2022-50965 tenable:nvd.nist.gov
- https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script tenable:www.apphp.com
- https://www.cve.org/CVERecord?id=CVE-2022-50965 tenable:www.cve.org
- https://www.exploit-db.com/exploits/50693 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.vulncheck.com/advisories/ubidauction-posts-manage-reflected-xss tenable:www.vulncheck.com
- https://www.vulnerability-lab.com/get_content.php?id=2289 tenable:www.vulnerability-lab.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script disclosure@vulncheck.com
- https://www.exploit-db.com/exploits/50693 disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/ubidauction-posts-manage-reflected-xss disclosure@vulncheck.com
- https://www.vulnerability-lab.com/get_content.php?id=2289 disclosure@vulncheck.com
Remediations (10)
-
web:community.ui.com
Published: May 21, 2026 Updated: May 22, 2026 Version: 1.1 Revision: 1.1 Summary 1 of 5 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. Affected Products: UniFi OS Server (Version 5.0.6 and earlier) Mitigation : Update your UniFi OS Server to Version 5.0.8 or later ...
2026-05-26 03:06 UTC -
web:my.f5.com
On October 15, 2025, F5 announced the following security issues. This document is intended to serve as an overview of these vulnerabilities and security exposures to help determine the impact to your F5 devices. You can find the details of each issue in the associated articles.
2026-05-26 03:06 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-26 03:06 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-26 03:06 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-26 03:06 UTC -
web:www.forbes.com
"Microsoft says it's rolling out an emergency patch that should address localhost-related issues in Windows 11 24H2/25H2, but remember, the hotfix could take longer than 48 hours to show on ...
2026-05-26 03:06 UTC -
web:www.howtogeek.com
In this case, use your PC's built-in Windows Update troubleshooter to automatically find and fix issues with your updates. Only a little interaction is required from your end. To run that tool, go to Settings > Update & Security > Troubleshoot > Additional Troubleshooters > Windows Update and click "Run the Troubleshooter".
2026-05-26 03:06 UTC -
web:www.ninjaone.com
Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.
2026-05-26 03:06 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-26 03:06 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-26 03:06 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.