In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An authenticated admin attacker can inject arbitrary javascript code that will execute on a victim’s server.
{ "versions": [ { "introduced": "1.0.0" }, { "last_affected": "1.4.17" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-22125.json"