VendorsHcltechconnectionsall versions
Vulnerabilities

Hcltech Connections

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2020-4085
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
Published 2020-04-22 · Modified
6.5EPSS 0.008
CVE-2023-28022
HCL Connections is vulnerable to sensitive information disclosure
Published 2023-12-15 · Modified
6.5EPSS 0.005
CVE-2024-30107
HCL Connections is vulnerable to broken access control
Published 2024-04-18 · Analyzed
6.5EPSS 0.003
CVE-2023-28018
HCL Connections s vulnerable to possible denial of service for certain users
Published 2024-02-12 · Modified
6.5EPSS 0.003
CVE-2025-52639
HCL Connections is vulnerable to sensitive information disclosure
Published 2025-11-18 · Analyzed
6.5EPSS 0.002
CVE-2019-4209
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
Published 2020-05-01 · Modified
6.1EPSS 0.006
CVE-2023-37533
HCL Connections is vulnerable to reflected cross-site scripting
Published 2023-11-08 · Modified
6.1EPSS 0.004
CVE-2024-30118
HCL Connections is susceptible to a sensitive information disclosure vulnerability
Published 2024-10-09 · Analyzed
5.7EPSS 0.003
CVE-2020-4083
HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.
Published 2020-03-05 · Modified
5.5EPSS 0.003
CVE-2020-4082
The HCL Connections 5.5 help system is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
Published 2020-03-05 · Modified
5.4EPSS 0.007
CVE-2020-4084
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published 2020-03-09 · Modified
5.4EPSS 0.005
CVE-2023-28017
HCL Connections is vulnerable to cross-site scripting
Published 2023-12-07 · Modified
5.4EPSS 0.004
CVE-2024-30112
HCL Connections is vulnerable to a cross-site scripting (XSS) vulnerability
Published 2024-06-25 · Analyzed
5.4EPSS 0.003
CVE-2026-21788
HCL Connections is vulnerable to cross-site scripting (XSS)
Published 2026-03-19 · Analyzed
5.4EPSS 0.002
CVE-2024-42188
HCL Connections is vulnerable to a broken access control vulnerability
Published 2024-11-14 · Analyzed
4.6EPSS 0.002
CVE-2025-31961
HCL Connections is vulnerable to broken access control
Published 2025-08-15 · Analyzed
4.6EPSS 0.002
CVE-2024-23557
HCL Connections is vulnerable to a user enumeration vulnerability
Published 2024-04-18 · Analyzed
4.3EPSS 0.003
CVE-2023-37541
HCL Connections is vulnerable to broken access control
Published 2024-06-25 · Analyzed
4.3EPSS 0.003
CVE-2024-30106
HCL Connections is vulnerable to an information disclosure vulnerability
Published 2024-10-28 · Analyzed
4.3EPSS 0.003
CVE-2026-56537
HCL Connections is vulnerable to information disclosure
Published 2026-07-27 · Analyzed
3.5EPSS 0.003
CVE-2026-56538
HCL Connections is vulnerable to information disclosure
Published 2026-07-27 · Analyzed
3.5EPSS 0.003
CVE-2024-42208
HCL Connections is vulnerable to an information disclosure vulnerability
Published 2025-04-04 · Analyzed
3.5EPSS 0.003
CVE-2025-52603
HCL Connections is vulnerable to information disclosure
Published 2026-02-20 · Analyzed
3.5EPSS 0.003
CVE-2024-42209
HCL Connections is vulnerable to an information disclosure vulnerability
Published 2025-07-17 · Analyzed
3.5EPSS 0.002