Unica

Vendor:

First CVE: May 12, 2022 · Active for 4 years

18
Total CVEs
More Total CVEs than 94% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unica over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2022
4 years ago
Most Recent CVE
Mar 19, 2026
131 days ago

CVE Severity & Scoring

Unica18 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (55.6%)
Unknown0 (0.0%)
Required8 (44.4%)
Privileges Required
Low6 (33.3%)
High0 (0.0%)
None12 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields
Mar 16, 20269.833NONO
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker could potentially escalate the
Aug 3, 20238.827NONO
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Nov 28, 20257.525NONO
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML Ex
Aug 3, 20238.825NONO
XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this v
May 12, 20227.525NONO
HCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private or system information that can
Oct 13, 20257.524NONO
HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may ins
Mar 17, 20266.122NONO
File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Nov 28, 20256.322NONO
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.
Oct 12, 20257.522NONO
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain types of
Oct 12, 20256.121NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Unica

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.1.1017.50.2%00
12.0.046.20.2%00