Skip to content
open-text-corporationCVE-2026-12559

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application.

High7.3CVE-2026-12559 · Published Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Vendor Invoice Management for SAP Solutions
Vendor
>= VIM 7.6/20.4, <= 0009No fix yet
>= VIM 23.4, <= 0004No fix yet
>= VIM 25.4, <= 0001No fix yet
Details and references

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:M/U:Red
Severity from
no source yet
Weakness
CWE-79

More open-text-corporation advisories

All
DateAdvisory
Sep 9Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS
CVE-2025-3271Medium4.8fixed in Documentum Webtop 16.7.1
Aug 17A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2.
CVE-2026-13202High7.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.