Skip to content
CVE-2025 and CVE-2022 Exploits Targeting Haraj Script

CVE-2025 and CVE-2022 Exploits Targeting Haraj Script

First seen 28 Sep 2026, 07:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 09:33 UTC
  • •CVE-2025 involves a POST request exploit affecting Haraj Script users.
  • •CVE-2022 is an authenticated stored XSS vulnerability in Haraj Script 3.7.
  • •Immediate action is recommended to address both vulnerabilities.

Recent reports detail two vulnerabilities, CVE-2025 and CVE-2022, affecting the Haraj Script. CVE-2025 involves a POST request exploit that could allow unauthorized transactions, impacting users of the Haraj platform. CVE-2022 is an authenticated stored XSS vulnerability in Haraj Script 3.7, potentially affecting users who authenticate on the platform. The exploit for CVE-2025 was disclosed on September 24, 2026, while CVE-2022 was reported on September 28, 2026. The scope of the impact for CVE-2025 is unclear, but it raises concerns about transaction security. The details of CVE-2022 indicate that it could allow attackers to execute scripts in the context of authenticated users. Both vulnerabilities require immediate attention from security professionals to mitigate risks. Currently, there are no confirmed reports of active exploitation for either CVE.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-24
CVE-2025 disclosed
A vulnerability in Haraj Script allows unauthorized transactions via a POST request exploit.
Sploitus
2026-09-28
CVE-2022 reported
An authenticated stored XSS vulnerability in Haraj Script 3.7 was disclosed, affecting authenticated users.
Sploitus

More articles in this cluster (2)