← All CVEs & advisories

ServiceNow CVE-2024-5890

ServiceNow Cross-Site Scripting

XSSCVSS 4.0 5.1Priority 10Disclosed 2024-12-02Verified

Risk & exploitation

PriorityLow · 10/100
EPSS0.004 · 60.3th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability could potentially enable an unauthenticated user to modify a web page or redirect users to another website.

ServiceNow released updates to customers that addressed this vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
Washington DCEarly Access
VancouverPatch 9 / Patch 10
UtahPatch 8 Hot Fix 1
Source & attribution

Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2024-5890 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.

Check your instance for CVE-2024-5890

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.