Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-32172

12
FAUCET Score

CVE-2022-32172 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Zinc versions v0.1.9 through v0.3.1. An authenticated attacker can inject a JavaScript payload into the template name field, which executes when another user deletes that template, potentially compromising user credentials. While no CVSS score is provided, the vulnerability has a FAUCET Risk Score of 4/100, indicating low severity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.1.9, <= 0.3.1CPE matchmatch criteria
cpe:2.3:a:zinclabs:zinc:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/zincsearch/zincsearchFixed in: 0.3.2
gopatch availablevia ghsa
Product: github.com/zinclabs/zincFixed in: 0.3.2

Vendor Advisories (1)

goGHSA-7j6x-42mm-p7jmmedium

Zinc Cross-site Scripting vulnerability

Jul 6, 2023

References

github.com / zinclabs/zinc/commit/3376c248bade163430f9347742428f0a82cd322d
PatchThird Party Advisory
mend.io / vulnerability-database/CVE-2022-32172
Third Party Advisory