Vulnerability Details CVE-2026-34495
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.
This issue affects FM Systems Employee: before 2025.3.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 34.4%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-34495
-
cpe:2.3:a:johnsoncontrols:fms_employee:*