Vendors · gainsight
Products (1)
Recent Vulnerabilities
View all 2 →CVE-2026-31382MEDIUM 6.1
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.
CVE-2026-31381MEDIUM 5.3
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
