Home/Product/hcltech unica
Product

hcltech unica

20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-42210
< 12.1.9
A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cross-site sc
7.6HIGH
CVE-2025-62320
< 12.1.11
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it
4.7MEDIUM
CVE-2025-51736
all versions
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
6.3MEDIUM
CVE-2025-51735
all versions
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
7.5HIGH
CVE-2025-51734
all versions
Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
5.4MEDIUM
CVE-2025-51733
all versions
Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
5.5MEDIUM
CVE-2025-31996
< 25.1.0.1
HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive informat
5.3MEDIUM
CVE-2025-52615
<= 25.1.0
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treat
3.5LOW
CVE-2025-52614
<= 25.1.0
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this
3.5LOW
CVE-2025-31969
<= 25.1.0
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting lo
4.0MEDIUM
CVE-2025-52616
all versions
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by lever
5.3MEDIUM
CVE-2023-37501
< 12.1.1
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's sessio
8.1HIGH
CVE-2023-37500
< 12.1.1
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could h
8.1HIGH
CVE-2023-37499
< 12.1.1
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker c
8.1HIGH
CVE-2023-37498
< 12.1.1
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possi
8.1HIGH
CVE-2023-37497
< 11.1.0.6
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker w
8.1HIGH
CVE-2021-27777
< 12.1.1
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without s
7.5HIGH
CVE-2008-7094
all versions
Campaign/CampaignListener in the listener server in Unica Affinium Campaign 7.2.1.0.55 allows remote attackers to cause a denial o
CVE-2008-7093
all versions
Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary
CVE-2008-7092
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitra
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin