Hcl Digital Experience
by HCLTech
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-4101 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2020 | "HCL Digital Experience is susceptible to Server Side Request Forgery." | ||
| CVE-2022-38662 | Med | 0.40 | 6.1 | 0.00 | Dec 19, 2022 | In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites. | ||
| CVE-2020-14222 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site). | ||
| CVE-2025-31988 | Med | 0.32 | 4.9 | 0.00 | Aug 19, 2025 | HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access. | ||
| CVE-2021-27774 | Low | 0.20 | 3.1 | 0.00 | Sep 22, 2022 | User input included in error response, which could be used in a phishing attack. |
- risk 0.64cvss 9.8epss 0.01
"HCL Digital Experience is susceptible to Server Side Request Forgery."
- risk 0.40cvss 6.1epss 0.00
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
- risk 0.40cvss 6.1epss 0.01
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
- risk 0.32cvss 4.9epss 0.00
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
- risk 0.20cvss 3.1epss 0.00
User input included in error response, which could be used in a phishing attack.