← Vulnerability feed

Vulnerability record · CVE-2022-27237 · published 21 April 2022

CVE-2022-27237: Ni flexlogger cross-site scripting vulnerability

NNi · Flexlogger

There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.

6.1 CVSS 3.1 Medium EPSS 0.56% · top 55.5% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-27237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-5022Ni labview path traversal vulnerabilityAbsolute path traversal vulnerability in the 3D Graph ActiveX control in cw3dgrph.ocx in National Instruments LabWindows/CVI 2012 SP1 and earlier, La…EPSS 2.6%9.3CVE-2013-5021Ni labview path traversal vulnerabilityMultiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlie…EPSS 2.1%8.8CVE-2025-2449Ni flexlogger path traversal vulnerabilityNI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create a…EPSS 34%8.5CVE-2026-64201Ni labview out-of-bounds read vulnerabilityThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  …EPSS 0.19%8.5CVE-2026-64202Ni labview out-of-bounds read vulnerabilityThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  …EPSS 0.19%8.5CVE-2026-64203Ni labview out-of-bounds read vulnerabilityThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  …EPSS 0.19%8.5CVE-2026-64204Ni labview out-of-bounds write vulnerabilityThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  …EPSS 0.19%8.5CVE-2026-16233Ni labview out-of-bounds write vulnerabilityThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  …EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2022-27237), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.