Product
hcltech digital experience
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-62326
CVE-2025-31988
CVE-2023-37538
CVE-2022-38653
CVE-2020-4081
CVE-2020-14255
CVE-2020-14221
CVE-2020-14223
all versions
HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would requir
all versions
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
all versions
HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected
all versions
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
all versions
In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).
all versions
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted
all versions
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
all versions
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflec