MEDIUM🇵🇱 Wersja polska

CVE-2026-21825

CVSS 6.1v3.1pub. 2026-06-05upd. 2026-06-10

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Hcltech Digital Experience

    APP
    Hcltech
    9.5
  • Hcltech Digital Experience Compose

    APP
    Hcltech
    9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2023-37538CRITICAL9.3PL ✓same product

Reflected XSS w HCL Digital Experience — wykonanie kodu w przeglądarce ofiary

CVE-2026-21837HIGH8.7same product

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management AP...

CVE-2020-14255HIGH7.5same product

HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized...

CVE-2026-21826MEDIUM6.1same product

HCL Digital Experience i HCL Digital Experience Compose mogą być podatne na Host header injection. Atakujący m...

CVE-2025-62326MEDIUM6.1same product

HCL Digital Experience jest podatny na stored XSS w interfejsie administratora, którego exploitacja wymaga pod...