VYPR

Domino Leap

by HCLTech

CVEs (9)

  • CVE-2023-37535HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.

  • CVE-2024-30145MedApr 30, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-30115MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2022-42450MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.

  • CVE-2022-42449MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

  • CVE-2022-27562MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

  • CVE-2024-30146MedApr 30, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2023-37517LowApr 30, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.