CVE-2026-34951
EUVD-2026-1935706.04.2026, 16:16
Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0, Workbench contains a reflected cross-site scripting vulnerability via the footerScripts parameter, which does not sanitize user-supplied input before rendering it in the page response. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Workbench allows XSS Targeting Error Pages. This vulnerability is fixed in 65.0.0.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| salesforce | workbench | 𝑥 < 65.0.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| forceworkbench | forceworkbench | 𝑥 < 65.0.0 | CNA |