CVE-2020-14222: Hcltech Hcl Digital Experience

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

Affected products

  • Hcltech Hcl Digital Experience: version 8.5 only; version 9.0 only; version 9.5 only

Published 2020-11-05. Last modified 2026-06-17.