Security Advisory
CVE-2026-34495
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.