← Vulnerability feed

Vulnerability record · CVE-2026-21825 · published 5 June 2026

CVE-2026-21825: Hcltech digital experience compose cross-site scripting vulnerability

Hcltech · Digital Experience Compose

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

6.1 CVSS 3.1 Medium EPSS 0.15% · top 96.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21825 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-21837Hcltech digital experience os command injection vulnerabilityHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary o…EPSS 0.92%7.5CVE-2020-14255Hcltech digital experience vulnerabilityHCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af…EPSS 1.1%6.1CVE-2026-21826Hcltech digital experience compose open redirect vulnerabilityHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header …EPSS 0.14%6.1CVE-2023-37538Hcltech digital experience cross-site scripting vulnerabilityHCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker m…EPSS 0.36%6.1CVE-2020-4081Hcltech digital experience cross-site scripting vulnerabilityIn Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).EPSS 0.63%6.1CVE-2020-14223Hcltech digital experience cross-site scripting vulnerabilityHCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persiste…EPSS 0.64%5.4CVE-2022-38653Hcltech digital experience cross-site scripting vulnerabilityIn HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.EPSS 0.30%4.9CVE-2020-14221Hcltech digital experience vulnerabilityHCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2026-21825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.