Cisco Unified Contact Center Express vulnerabilities
45 known vulnerabilities affecting cisco/unified_contact_center_express.
Total CVEs
45
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH16MEDIUM22
Vulnerabilities
Page 3 of 3
CVE-2016-1298P4MEDIUMCVSS 6.1v10.0\(1\)v10.5\(1\)+2 more2016-01-26
CVE-2016-1298 [MEDIUM] CWE-79 CVE-2016-1298: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1),
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.
nvd
CVE-2016-6425P4MEDIUMCVSS 6.1v10.0\(1\)v10.5\(1\)+2 more2016-10-06
CVE-2016-6425 [MEDIUM] CWE-79 CVE-2016-6425: Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
nvd
CVE-2011-2583P4MEDIUMCVSS 5.0v8.0v8.52012-05-02
CVE-2011-2583 [MEDIUM] CWE-20 CVE-2011-2583: Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial
Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated by an SEC-BE-STABLE test case, aka Bug ID CSCth33834.
nvd
CVE-2025-20279P4MEDIUMCVSS 4.8v8.5\(1\)v9.0\(2\)su3es04+58 more2025-06-04
CVE-2025-20279 [MEDIUM] CWE-79 CVE-2025-20279: A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authentica
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to improper sanitization of user input to the web-based manage
nvd
CVE-2019-12626P4MEDIUMCVSS 4.8v12.5\(1\)2019-08-21
CVE-2019-12626 [MEDIUM] CWE-20 CVE-2019-12626: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied
nvd
← Previous3 / 3