← Back

Genesys

genesys

8 CVEs • 7 products

Products (7)

Click to collapse
Toggle

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Genesys
1Latitude
Jun 10, 2026
Apr 21, 2026
N/A· v4
N/A· v3
N/A· v2
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
1Genesys
1Administrator Extension
Jun 17, 2026
Aug 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.
1Genesys
1Tftp Server
Jun 17, 2026
May 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.
1Genesys
1Pureconnect
Jul 9, 2026
Sep 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
1Genesys
1Workforce Management
Jul 9, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.
1Genesys
1Intelligent Workload Distribution Manager
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the d...Show more
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.Show less
1Genesys
1Intelligent Workload Distribution Manager
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which al...Show more
A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.Show less
1Genesys
1Eservices Chat
Jun 17, 2026
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).