CVE-2026-21825: Hcltech Digital Experience
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
Affected products
Published 2026-06-05. Last modified 2026-07-23.