Gainsight develops customer success and revenue intelligence platforms, with observed vulnerabilities concentrating in its Assist product around web application input handling and HTTP request mechanisms. The recurring weakness classes reflect typical input-validation and data-transmission concerns in SaaS application layers; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gainsight over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31382MEDIUM The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload. | Mar 20, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-31381MEDIUM An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL. | Mar 20, 2026 | 5.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gainsight.
Media articles that mention a CVE ID that affects a product developed by Gainsight — matched by CVE ID, not by vendor name.