🔐 CVE Alert

CVE-2026-67075

MEDIUM 6.5

HCL Digital Experience is affected by improper input sanitation

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

HCL Digital Experience is affected by improper input sanitation.  This can result in HTML injection which could be leveraged in content spoofing from a trusted domain. Apply HCL Digital Experience 9.5 CF238 or later to address this.

CWE CWE-79
Vendor hclsoftware
Product digital experience
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for hclsoftware digital experience

Be the first to know when new medium vulnerabilities affecting hclsoftware digital experience are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

HCLSoftware / Digital Experience
9.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.hcl-software.com: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133995