Description Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. Remediation References CVE-2022-37251 Related Vulnerabilities WebLogic CVE-2022-21306 Vulnerability (CVE-2022-21306) WordPress Plugin Advanced Forms for ACF Pro Security Bypass (1.6.8) Python Uncontrolled Search Path Element Vulnerability (CVE-2017-20052) Ruby CVE-2019-15845 Vulnerability (CVE-2019-15845) LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-5017) Severity Medium Classification CVE-2022-37251 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities