CVE-2025-31969: Hcltech Unica

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of attacks, such as cross-site scripting and clickjacking.

Affected products

  • Hcltech Unica: up to and including 25.1.0

Published 2025-10-12. Last modified 2026-10-08.