Skip to main content

Vendor/product archive

johnsoncontrols / fms_employee CVEs

Beta · best-effort

3 CVEs tagged to johnsoncontrols / fms_employee0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-34497

Published Jul 31, 2026

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34495

Published Jul 31, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects F…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-21662

Published Jul 31, 2026

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1