Known vulnerabilities in Qlik Sense Enterprise for Windows
Vendor:
QlikTech International AB
Software:
Qlik Sense Enterprise for Windows
Software CPE:
cpe:2.3:a:qlik:qlik_sense_enterprise_for_windows:*:*:*:*:*:*:*:*
Website:
https://www.qlik.com/
Total vulnerabilities:
8
Public exploits:
3
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
May 2026 IR
May 2024 Patch 24
November 2024 Patch 18
May 2025 Patch 6
February 2023 Patch 16
May 2023 Patch 19
August 2023 Patch 17
November 2023 Patch 17
February 2024 Patch 15
May 2024 Patch 11
February 2023 Patch 15
May 2023 Patch 18
August 2023 Patch 16
November 2023 Patch 16
February 2024 Patch 14
May 2024 Patch 10
November 2024
February 2023 Patch 14
May 2023 Patch 17
August 2023 Patch 15
November 2023 Patch 15
February 2024 Patch 13
May 2024 Patch 9
November 2021 Patch 17
February 2022 Patch 15
May 2022 Patch 16
August 2022 Patch 14
November 2022 Patch 12
February 2023 Patch 10
May 2023 Patch 6
August 2023 Patch 2
August 2022 Patch 13
November 2022 Patch 11
February 2023 Patch 8
May 2023 Patch 4
August 2023
August 2022 Patch 12
November 2022 Patch 10
February 2023 Patch 7
May 2023 Patch 3
14.44.0
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU113173 - Use of Insufficiently Random Values CVE-2025-7783 |
CWE-330 | Medium | May 2025 Patch 6, November 2024 Patch 18, May 2024 Patch 24 | 23.07.2025 |
SB2025072332 SB2025072333 SB2025081876 and 62 more |
||
| #VU111081 - Improper Access Control CVE-2024-55580 |
CWE-284 | High | August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18 | 11.06.2025 |
SB2025061178 |
||
| #VU111080 - Permissions, Privileges, and Access Controls CVE-2024-55579 |
CWE-264 | High | August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18 | 11.06.2025 |
SB2025061178 |
||
| #VU83603 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-48365 |
CWE-444 | High | August 2022 Patch 14, August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, February 2022 Patch 15, May 2022 Patch 16, November 2021 Patch 17 | 30.11.2023 |
SB2023113053 |
||
| #VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2023-26136 |
CWE-1321 | High | May 2025 Patch 6, November 2024 Patch 18, May 2024 Patch 24 | 04.09.2023 |
SB2023090411 SB2023090423 SB2023090816 and 42 more |
||
| #VU80196 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-41266 |
CWE-22 | High | August 2022 Patch 13, August 2023, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11 | 31.08.2023 |
SB2023083126 |
||
| #VU80193 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-41265 |
CWE-444 | High | August 2022 Patch 13, August 2023, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11 | 31.08.2023 |
SB2023083126 |
||
| #VU60748 - Exposure of sensitive information to an unauthorized actor CVE-2022-0564 |
CWE-200 | Medium | 14.44.0 | 22.02.2022 |
SB2022022204 |