CVE-2026-31822 | Sylius up to 2.0.15/2.1.11/2.2.2 Message cross site scripting (GHSA-vgh8-c6fp-7gcg)
A vulnerability was found in Sylius up to 2.0.15/2.1.11/2.2.2. It has been classified as problematic. This affects an unknown function of the component Message Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-31822. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.