Mieweb's vulnerability footprint centers on its Enterprise Health electronic health record platform, a healthcare-focused application where vulnerabilities skew toward serious outcomes including critical severity. The recurring weakness classes reflect application-layer security issues endemic to web-based health systems: cross-site scripting, cross-site request forgery, debug information disclosure, CSV formula injection, and unrestricted file uploads that can compound access and data-integrity risks in a clinical environment. Defenders should prioritize updates to this vendor's products given the sensitive nature of health data and the severity profile; live exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mieweb over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-35032CRITICAL Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is | Sep 29, 2025 | 9.9 | 30 | NO | NO |
CVE-2025-35030HIGH Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking | Sep 29, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-35034MEDIUM Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can | Sep 29, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-35029MEDIUM Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic | Nov 20, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-35031MEDIUM Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, | Sep 29, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-35033MEDIUM Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This is | Sep 29, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mieweb.
Media articles that mention a CVE ID that affects a product developed by Mieweb — matched by CVE ID, not by vendor name.