Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-32171

12
FAUCET Score

CVE-2022-32171 describes a Stored Cross-Site Scripting (XSS) vulnerability in Zinc versions v0.1.9 through v0.3.1. This flaw allows an authenticated attacker to inject a malicious JavaScript payload into the user ID field, which executes when another authenticated user attempts to delete that user. Successful exploitation could lead to credential theft. While the CVSS score is unavailable, the FAUCET Risk Score is low at 4/100, and there is no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.1.9, <= 0.3.1CPE matchmatch criteria
cpe:2.3:a:zinclabs:zinc:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/zincsearch/zincsearchFixed in: 0.3.2
gopatch availablevia ghsa
Product: github.com/zinclabs/zincFixed in: 0.3.2

Vendor Advisories (1)

goGHSA-4fgv-8448-gf82medium

Zinc Cross-site Scripting vulnerability

Jul 6, 2023

References

github.com / zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d
PatchThird Party Advisory
mend.io / vulnerability-database/CVE-2022-32171
Third Party Advisory