Commvault Vulnerabilities and Affected Products
Vulnerabilities associated with WebConsole.
Products
Clear product- CommCell9 vulnerabilities
- Commvault3 vulnerabilities
- Commvault Cloud3 vulnerabilities
- Command Center1 vulnerability
- Command Center Innovation Release1 vulnerability
- Commvault for Windows1 vulnerability
- Service Pack 61 vulnerability
- Web Server1 vulnerability
- WebConsole1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Stored Cross-Site ScriptingThe Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a secure and seamless user experience. Although the user input is not validated in the report creation, these scripts are not executed when the report is run by end users. The script is executed when the report is modified through the report builder b… CWE-79Jan 7, 2026 | CVSS1.8v4.0 | EPSS0.151% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |