Home

Description

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.

PUBLISHED Reserved 2026-01-05 | Published 2026-06-05 | Updated 2026-06-09 | Assigner HCL




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

Product status

Default status
unaffected

9.5
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0130849

cve.org (CVE-2026-21825)

nvd.nist.gov (CVE-2026-21825)

Download JSON