cbcvebase.

Cisco Unified Contact Center Express vulnerabilities

36 known vulnerabilities affecting cisco/cisco_unified_contact_center_express.

Total CVEs
36
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH9MEDIUM23

Vulnerabilities

Page 2 of 2
CVE-2026-20116P4MEDIUMCVSS 6.1v10.5(1)SU1v10.6(1)+60 more2026-03-11
CVE-2026-20116 [MEDIUM] CWE-79 CVE-2026-20116: A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct cross-site scriptin
nvd
CVE-2026-20117P4MEDIUMCVSS 6.1v10.5(1)SU1v10.6(1)+60 more2026-03-11
CVE-2026-20117 [MEDIUM] CWE-79 CVE-2026-20117: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently val
nvd
CVE-2025-20129P4MEDIUMCVSS 5.4v10.6(1)v10.5(1)SU1+58 more2025-06-04
CVE-2025-20129 [MEDIUM] CWE-200 CVE-2025-20129: A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), form A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could
nvd
CVE-2019-1670P4MEDIUMCVSS 6.1vn/a2019-02-07
CVE-2019-1670 [MEDIUM] CWE-79 CVE-2019-1670: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could
nvd
CVE-2019-15259P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-15259 [MEDIUM] CWE-113 CVE-2019-15259: A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticat A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by co
nvd
CVE-2021-1358P4MEDIUMCVSS 6.1vn/a2021-05-22
CVE-2021-1358 [MEDIUM] CWE-601 CVE-2021-1358: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2021-1463P4MEDIUMCVSS 6.1vn/a2021-04-08
CVE-2021-1463 [MEDIUM] CWE-79 CVE-2021-1463: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacke
nvd
CVE-2021-1395P4MEDIUMCVSS 6.1vn/a2021-06-16
CVE-2021-1395 [MEDIUM] CWE-79 CVE-2021-1395: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could
nvd
CVE-2023-20058P4MEDIUMCVSS 6.1v11.0(1)SU1v12.0(1)+5 more2023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
nvd
CVE-2023-20096P4MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20096 [MEDIUM] CWE-79 CVE-2023-20096: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by entering craf
nvd
CVE-2025-20112P4MEDIUMCVSS 5.1v10.5(1)SU1v10.6(1)+59 more2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing craf
nvd
CVE-2025-20114P4MEDIUMCVSS 4.3v10.6(1)v10.5(1)SU1+58 more2025-05-21
CVE-2025-20114 [MEDIUM] CWE-639 CVE-2025-20114: A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted
nvd
CVE-2025-20377P4MEDIUMCVSS 4.3v10.5(1)SU1v10.6(1)+55 more2025-11-05
CVE-2025-20377 [MEDIUM] CWE-200 CVE-2025-20377: A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticat A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific
nvd
CVE-2025-20279P4MEDIUMCVSS 4.8v10.6(1)v10.5(1)SU1+58 more2025-06-04
CVE-2025-20279 [MEDIUM] CWE-79 CVE-2025-20279: A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authentica A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper sanitization of user input to the web-based manage
nvd
CVE-2021-1254P4MEDIUMCVSS 4.8vn/a2021-05-22
CVE-2021-1254 [MEDIUM] CWE-79 CVE-2021-1254: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authe Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An a
nvd
CVE-2019-12626P4MEDIUMCVSS 4.8≥ unspecified, < 12.0(1)ES022019-08-21
CVE-2019-12626 [MEDIUM] CWE-20 CVE-2019-12626: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied
nvd
Cisco Unified Contact Center Express vulnerabilities | cvebase