CVE-2026-34495

CVE-2026-34495CVE-2026-34495

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

Scoring

Last modified2026-07-31
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.