← Vulnerability feed

Vulnerability record · CVE-2015-2522 · published 9 September 2015

CVE-2015-2522: Microsoft sharepoint foundation cross-site scripting vulnerability

Microsoft · Sharepoint Foundation

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."

3.5 CVSS 2.0 Low EPSS 10% · top 4.4% CWE-79 · Cross-site scripting
3.5CVSS 2.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vulnerability."

AV:N/AC:M/Au:S/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2522 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed10.0CVE-2013-1330Microsoft sharepoint foundation improper input validation vulnerabilityThe default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 d…EPSS 27%9.9CVE-2020-1595Microsoft sharepoint enterprise server download of code without integrity check vulnerability<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who …EPSS 2.0%9.9CVE-2020-1210Microsoft sharepoint enterprise server download of code without integrity check vulnerability<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.…EPSS 1.9%9.8CVE-2023-21716Microsoft Word integer overflow remote code executionCVE-2023-21716 is a critical remote code execution flaw in Microsoft Word, tied to an integer overflow (CWE-190). The record gives only a one-line de…EPSS 85%analysed9.8CVE-2020-1025Microsoft lync improper input validation vulnerabilityAn elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validatio…EPSS 5.9%9.3CVE-2015-1682Microsoft excel memory buffer overflow vulnerabilityMicrosoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, O…EPSS 19%9.3CVE-2015-0085Microsoft excel vulnerabilityUse-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, Power…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2015-2522), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.