CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

hcltechsw

hcl_commerce

7 known vulnerabilities · sorted by CVSS score

CVE-2020-14275
CRITICAL9.8

Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce+2
Network
Published Jan 12, 2021
CVE-2021-27741
CRITICAL9.1

" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

hcltechsw / hcl_commerce+2
Network
Published Aug 13, 2021
CVE-2022-38656
HIGH8.6

HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

hcltechsw / hcl_commerce
Network
Published Dec 12, 2022
CVE-2020-14274
HIGH7.5

Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.

hcltechsw / hcl_commerce+1
Network
Published Jan 12, 2021
CVE-2024-23576
HIGH7.1

Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

hcltechsw / hcl_commerce
Network
Published May 14, 2024
CVE-2021-27751
MEDIUM4.4

HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circumstances, parts of the application are still accessible.

hcltechsw / hcl_commerce+2
Local
Published May 6, 2022
CVE-2021-27785
LOW3.9

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerability requires the victim to first perform a particular operation on the website.

hcltechsw / hcl_commerce+1
Physical
Published Jul 30, 2022