Hcl Leap

Vendor:

First CVE: Feb 12, 2023 · Active for 3 years

11
Total CVEs
More Total CVEs than 90% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
4.9
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hcl Leap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2023
3 years ago
Most Recent CVE
Apr 24, 2025
460 days ago

CVE Severity & Scoring

Hcl Leap11 CVEs
All CVEs353,240 CVEs
LowMedium
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None2 (18.2%)
Unknown0 (0.0%)
Required9 (81.8%)
Privileges Required
Low7 (63.6%)
High1 (9.1%)
None3 (27.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
Apr 24, 20255.419NONO
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
Apr 24, 20256.118NONO
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
Apr 24, 20256.118NONO
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
Apr 24, 20255.317NONO
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
Apr 24, 20255.416NONO
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
Apr 24, 20255.415NONO
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
Feb 12, 20235.415NONO
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
Apr 24, 20253.214NONO
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
Apr 24, 20254.614NONO
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
Apr 24, 20254.114NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Hcl Leap

Top CWEs

Versions

No cataloged versions.