CVE-2025-47977: Microsoft Nuance Digital Engagement Platform
High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.
Affected products
- Microsoft Nuance Digital Engagement Platform: before 5.64.x (fixed in 5.64.x)
Published 2025-06-10. Last modified 2026-06-17.