HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:NHcltech Digital Experience
APPHcltech9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2023-37538CRITICAL9.3PL ✓same product
Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary
CVE-2026-21837HIGH8.7same product
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...
CVE-2020-14255HIGH7.5same product
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...
CVE-2026-21826MEDIUM6.1same product
HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...
CVE-2026-21825MEDIUM6.1same product
HCL Digital Experience Compose jest podatny na reflected XSS w komponencie search center. Atakujący mógłby wyk...