Unica
Vendor:
First CVE: May 12, 2022 · Active for 4 years
18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Unica over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2022
4 years ago
Most Recent CVE
Mar 19, 2026
131 days ago
CVE Severity & Scoring
Unica18 CVEs
61%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (55.6%)
Unknown0 (0.0%)
Required8 (44.4%)
Privileges Required
Low6 (33.3%)
High0 (0.0%)
None12 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62319CRITICAL Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields | Mar 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2023-37498HIGH A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator. It is possible that an attacker could potentially escalate the | Aug 3, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-51735HIGH CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. | Nov 28, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-37497HIGH The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML Ex | Aug 3, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-27777HIGH XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this v | May 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-31996HIGH HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can | Oct 13, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-62320MEDIUM HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may ins | Mar 17, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-51736MEDIUM File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. | Nov 28, 2025 | 6.3 | 22 | NO | NO |
CVE-2025-52616HIGH HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application. | Oct 12, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-31969MEDIUM HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of | Oct 12, 2025 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Unica
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.1.10 | 1 | 7.5 | 0.2% | 0 | 0 |
| 12.0.0 | 4 | 6.2 | 0.2% | 0 | 0 |