Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qlik

First CVE: Sep 16, 2015Active for: 11 yearsTotal CVEs: 11
54.6
VTI Score
TOP TARGET

Qlik's vulnerability footprint centers on a small but prominent portfolio of business-intelligence and analytics products—including Qlik Sense, QlikView, and NPrinting Designer—that are widely deployed in enterprise data environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation and public exploit availability; the exposure recurs through web-layer weakness classes including HTTP request smuggling, path traversal, cross-site scripting, and expression-language injection that are characteristic of server-side request processing and template rendering. Defenders should treat Qlik advisories as high-priority for internet-facing or network-accessible deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
27.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Qlik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2015
10 years ago
Most Recent CVE
Nov 20, 2025
247 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-41265CRITICAL
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch
Aug 29, 20239.997YESYES
CVE-2023-41266MEDIUM
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and e
Aug 29, 20236.595YESYES
CVE-2023-48365CRITICAL
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attack
Nov 15, 20239.981YESNO
CVE-2015-3623MEDIUM
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary file
Sep 16, 20156.432NOYES
CVE-2021-41989HIGH
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
Jan 26, 20237.825NONO
CVE-2021-41988HIGH
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
Jan 26, 20237.825NONO
CVE-2025-61138HIGH
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
Nov 20, 20257.524NONO
CVE-2019-11628MEDIUM
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytic
May 1, 20196.523NONO
CVE-2022-42248MEDIUM
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
Mar 6, 20235.422NONO
CVE-2022-0564MEDIUM
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authen
Feb 21, 20225.321NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
27%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (18.2%)
Network8 (72.7%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High0 (0.0%)
Unknown1 (9.1%)
User Interaction
None9 (81.8%)
Unknown1 (9.1%)
Required1 (9.1%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None4 (36.4%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
3 CVEs
27.3% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
18.2% of CVEs· 97th percentile
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qlik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qlik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qlik's Products

View all 2 CNAs →

Top CWEs