Showing 2 vulnerabilities on this page for Digital Experience

Signals CISA KEV Ransomware Nuclei
HCLSoftware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

CWE-78Jun 5, 2026
CVSS8.7v4.0EPSS0.92%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

HCL Digital Experience is susceptible to stored cross-site scripting (XSS)

HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which would require elevated privileges to exploit.

CWE-79Feb 20, 2026
CVSS6.1v3.1EPSS0.154%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX