Vulnerabilities > Mendix > Mendix

DATE CVE VULNERABILITY TITLE RISK
2023-02-14 CVE-2023-23835 Improper Access Control vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15).
network
low complexity
mendix CWE-284
7.5
2022-07-12 CVE-2022-31257 Unspecified vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12).
network
low complexity
mendix
7.5
2022-07-12 CVE-2022-34466 Expression Language Injection vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3).
network
low complexity
mendix CWE-917
6.5
2022-04-12 CVE-2022-25650 Unspecified vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.3).
network
low complexity
mendix
6.5
2022-04-12 CVE-2022-27241 Information Exposure vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.11), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12).
network
low complexity
mendix CWE-200
5.0
2022-03-08 CVE-2022-24309 Unspecified vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29), Mendix Applications using Mendix 8 (All versions < V8.18.16), Mendix Applications using Mendix 9 (All deployments with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False).
network
low complexity
mendix
8.1
2022-03-08 CVE-2022-26317 Use of Insufficiently Random Values vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29).
network
low complexity
mendix CWE-330
6.5
2021-11-09 CVE-2021-42015 Information Exposure Through Browser Caching vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1).
local
mendix CWE-525
1.9
2021-11-09 CVE-2021-42025 Incorrect Authorization vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2).
network
low complexity
mendix CWE-863
6.8
2021-11-09 CVE-2021-42026 Incorrect Authorization vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2).
network
low complexity
mendix CWE-863
4.0