CVE-2026-34495
CVE-2026-34495CVE-2026-34495
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.
This issue affects FM Systems Employee: before 2025.3.1.
Scoring
| Last modified | 2026-07-31 |