CVE-2026-21825 PUBLISHED

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center

Assigner: HCL
Reserved: 05.01.2026 Published: 05.06.2026 Updated: 05.06.2026

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 6.1

Product Status

Vendor HCLSoftware
Product DX Compose
Versions Default: unaffected
  • Version 9.5 is affected

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE