Skip to main content

Vendor/product archive

hcltech / connections CVEs

Beta · best-effort

22 CVEs tagged to hcltech / connections0 Critical, 0 High, 10 Medium, 12 Low, 0 Unrated.

CVE-2026-21788

Published Mar 19, 2026

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user wh…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52603

Published Feb 20, 2026

HCL Connections is vulnerable to information disclosure. In a very specific user navigation scenario, this could allow a user to obtain limited information when a single piece of…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52639

Published Nov 18, 2025

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by impr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-31961

Published Aug 15, 2025

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42209

Published Jul 17, 2025

HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is caused by impro…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42208

Published Apr 4, 2025

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper hand…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42188

Published Nov 14, 2024

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30106

Published Oct 28, 2024

HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive informatio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30118

Published Oct 9, 2024

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly ha…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30112

Published Jun 25, 2024

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user wh…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37541

Published Jun 25, 2024

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30107

Published Apr 18, 2024

HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-23557

Published Apr 18, 2024

HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force atta…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28018

Published Feb 12, 2024

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerabi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28022

Published Dec 15, 2023

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper hand…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28017

Published Dec 7, 2023

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user af…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37533

Published Nov 9, 2023

HCL Connections is vulnerable to reflected cross-site scripting (XSS) where an attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspectin…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4209

Published May 1, 2020

HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4085

Published Apr 22, 2020

"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4084

Published Mar 9, 2020

HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the int…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4083

Published Mar 5, 2020

HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4082

Published Mar 5, 2020

The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1