Hcl Leap
Vendor:
First CVE: Feb 12, 2023 · Active for 3 years
11
Total CVEs
More Total CVEs than 90% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
4.9
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hcl Leap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2023
3 years ago
Most Recent CVE
Apr 24, 2025
460 days ago
CVE Severity & Scoring
Hcl Leap11 CVEs
18%
82%
All CVEs353,240 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None2 (18.2%)
Unknown0 (0.0%)
Required9 (81.8%)
Privileges Required
Low7 (63.6%)
High1 (9.1%)
None3 (27.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44759MEDIUM Improper sanitization of SVG files in HCL Leap
allows client-side script injection in deployed applications. | Apr 24, 2025 | 5.4 | 19 | NO | NO |
CVE-2024-30147MEDIUM Multiple vectors in HCL Leap allow client-side
script injection in the authoring environment and deployed applications. | Apr 24, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-37534MEDIUM Insufficient URI protocol whitelist in HCL Leap
allows script injection through query parameters. | Apr 24, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-45720MEDIUM Insufficient default configuration in HCL Leap
allows anonymous access to directory information. | Apr 24, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-30114MEDIUM Insufficient sanitization in HCL Leap allows
client-side script injection in the authoring environment. | Apr 24, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-30113MEDIUM Insufficient sanitization policy in HCL Leap
allows client-side script injection in the deployed application through the
HTML widget. | Apr 24, 2025 | 5.4 | 15 | NO | NO |
CVE-2022-38657MEDIUM An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
| Feb 12, 2023 | 5.4 | 15 | NO | NO |
Missing "no cache" headers in HCL Leap permits user directory information to be cached. | Apr 24, 2025 | 3.2 | 14 | NO | NO |
CVE-2022-44760MEDIUM Unsafe default file type filter policy in HCL
Leap allows execution of unsafe JavaScript in deployed applications. | Apr 24, 2025 | 4.6 | 14 | NO | NO |
CVE-2024-30148MEDIUM Improper access control of endpoint in HCL Leap
allows certain admin users to import applications from the
server's filesystem. | Apr 24, 2025 | 4.1 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Hcl Leap
Top CWEs
Versions
No cataloged versions.