Vulnerability Database

313,519

Total vulnerabilities in the database

CVE-2022-43561

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

  • Published: Nov 3, 2022
  • Updated: Nov 16, 2025
  • CVE: CVE-2022-43561
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.4
  • AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H