CVE-2026-21768: Hclsoftware Verse For Android
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
Affected products
- Hclsoftware Verse For Android: version 14.5.10 only
Published 2026-06-19. Last modified 2026-06-22.