Salesforce, Inc.
First CVE: Aug 30, 2019Active for: 7 years
45
CVEs Published
More CVEs Published than 55% of tracked CNAs
7.5
Avg CVEs / Year
More Avg CVEs / Year than 45% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 85% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Salesforce, Inc. as a CNA, 33.3% affect products that Salesforce, Inc. develops as a vendor.
33.3%
66.7%
Self-reported: 15Third-party: 30
Of all the CVEs published that affect products developed by Salesforce, Inc., 75.0% are self-published by Salesforce, Inc. as a CNA.
75.0%
25.0%
Self-published: 15Published by other CNAs: 5
Trends Over Time
The number and severity of CVEs published by Salesforce, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2019
6 years ago
Most Recent CVE
Mar 23, 2026
123 days ago
Top CVEs
All CVEs published by Salesforce, Inc. as a CNA, regardless of affected vendor or product.
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22583CRITICAL Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services | Jan 24, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22582CRITICAL Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services | Jan 24, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-22586CRITICAL Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Web | Jan 24, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-22584CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This i | Jan 9, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-26496CRITICAL Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code | Aug 22, 2025 | 9.3 | 33 | NO | NO |
CVE-2026-22585CRITICAL Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub | Jan 24, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-9844HIGH Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6. | Sep 23, 2025 | 8.8 | 30 | NO | NO |
CVE-2022-22128CRITICAL Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only | Oct 17, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-1628CRITICAL MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affect | Mar 26, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1626CRITICAL MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions a | Mar 26, 2021 | 9.8 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA45 CVEs
22%
47%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.2%)
Network41 (91.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (6.7%)
Attack Complexity
Low43 (95.6%)
High2 (4.4%)
Unknown0 (0.0%)
User Interaction
None41 (91.1%)
Unknown0 (0.0%)
Required4 (8.9%)
Privileges Required
Low7 (15.6%)
High1 (2.2%)
None37 (82.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Salesforce, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Salesforce, Inc. as a CNA — matched by CVE ID, not by organization name.