CVE-2025-31992: Hcl Software Maxai Assistant

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.

Affected products

Published 2025-10-12. Last modified 2026-10-08.