Vulnerability Description
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains a reflected cross-site scripting vulnerability via the footerScripts parameter, which does not sanitize user-supplied input before rendering it in the page response. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Workbench allows XSS Targeting Error Pages. This vulnerability is fixed in 65.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Salesforce | Workbench | < 65.0.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-34951?
CVE-2026-34951 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains a reflected cross-site scripti...
How severe is CVE-2026-34951?
CVE-2026-34951 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34951?
Check the references section above for vendor advisories and patch information. Affected products include: Salesforce Workbench.