Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39357

30
FAUCET Score

CVE-2022-39357 is a critical prototype pollution vulnerability affecting the Snowboard framework in Winter CMS versions 1.1.8, 1.1.9, and 1.2.0. This flaw allows an unauthenticated attacker to achieve high impact on confidentiality, integrity, and availability with low attack complexity, evidenced by its CVSS score of 9.8. While no active exploitation, public exploit code, or significant community discussion has been observed, affected organizations should prioritize patching to versions 1.1.10 or 1.2.1, or implement JavaScript security best practices as a workaround.

Impacted Technologies

VendorProductVersion(s)CPE
1.1.8CPE matchmatch criteria
cpe:2.3:a:wintercms:winter:1.1.8:*:*:*:*:*:*:*
1.1.9CPE matchmatch criteria
cpe:2.3:a:wintercms:winter:1.1.9:*:*:*:*:*:*:*
1.2.0CPE matchmatch criteria
cpe:2.3:a:wintercms:winter:1.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.03%
Probability of exploitation in next 30 days
EPSS Percentile
60.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0103 is in the 45th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: wintercms/winterFixed in: 1.1.10
composerpatch availablevia ghsa
Product: wintercms/winterFixed in: 1.2.1
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-3fh5-q6fg-w28qhigh

Prototype pollution in Snowboard framework

Oct 27, 2022

References

github.com / wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1
PatchThird Party Advisory
github.com / wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f
PatchThird Party Advisory
github.com / wintercms/winter/releases/tag/v1.1.10
Release NotesThird Party Advisory
github.com / wintercms/winter/releases/tag/v1.2.1
Release NotesThird Party Advisory
github.com / wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q
PatchThird Party Advisory