CVE-2025-47977: Microsoft Nuance Digital Engagement Platform

High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.

Affected products

  • Microsoft Nuance Digital Engagement Platform: before 5.64.x (fixed in 5.64.x)

Published 2025-06-10. Last modified 2026-06-17.