Qlik's vulnerability footprint centers on a small but prominent portfolio of business-intelligence and analytics products—including Qlik Sense, QlikView, and NPrinting Designer—that are widely deployed in enterprise data environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation and public exploit availability; the exposure recurs through web-layer weakness classes including HTTP request smuggling, path traversal, cross-site scripting, and expression-language injection that are characteristic of server-side request processing and template rendering. Defenders should treat Qlik advisories as high-priority for internet-facing or network-accessible deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qlik over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41265CRITICAL An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch | Aug 29, 2023 | 9.9 | 97 | YES | YES |
CVE-2023-41266MEDIUM A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and e | Aug 29, 2023 | 6.5 | 95 | YES | YES |
CVE-2023-48365CRITICAL Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attack | Nov 15, 2023 | 9.9 | 81 | YES | NO |
CVE-2015-3623MEDIUM XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary file | Sep 16, 2015 | 6.4 | 32 | NO | YES |
CVE-2021-41989HIGH Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions. | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2021-41988HIGH Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions. | Jan 26, 2023 | 7.8 | 25 | NO | NO |
CVE-2025-61138HIGH Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. | Nov 20, 2025 | 7.5 | 24 | NO | NO |
CVE-2019-11628MEDIUM An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytic | May 1, 2019 | 6.5 | 23 | NO | NO |
CVE-2022-42248MEDIUM QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality. | Mar 6, 2023 | 5.4 | 22 | NO | NO |
CVE-2022-0564MEDIUM A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authen | Feb 21, 2022 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qlik.
Media articles that mention a CVE ID that affects a product developed by Qlik — matched by CVE ID, not by vendor name.