← All CVEs & advisories

ServiceNow CVE-2023-1209

ServiceNow Cross-Site Scripting

XSSCVSS 3.1 4.3Priority 9Disclosed 2023-05-23Verified

Risk & exploitation

PriorityLow · 9/100
EPSS0.007 · 73.2th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
UtahPatch 1
TokyoPatch 4a / Patch 5
San DiegoPatch 9a / Patch 10
RomePatch 10 Hot Fix 4b
Source & attribution

Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2023-1209 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.

Check your instance for CVE-2023-1209

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.