Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Salesforce, Inc.

First CVE: Oct 4, 2017Active for: 9 yearsTotal CVEs: 20
28.6
VTI Score
Low

Salesforce's vulnerability footprint spans a small but prominently deployed set of cloud-based customer-engagement, integration, and AI platform products that occupy a high-value position in enterprise software stacks. While the vendor's disclosed vulnerability volume remains modest in absolute terms, vulnerabilities affecting Salesforce skew strongly toward critical-severity outcomes, reflecting the trust boundary between the platform and customer data. The recurring exposure concentrates in products such as Marketing Cloud Engagement, Mule, and the Anypoint integration platform and centers on code-injection, argument-injection, XML entity-reference handling, and permission-assignment weaknesses that arise from dynamic code execution, templating, and configuration-parsing surfaces. Defenders should prioritize patching for these products given their integration depth and data-handling scope; current severity, exploitation, and product-coverage details are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Salesforce, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2017
8 years ago
Most Recent CVE
Apr 6, 2026
109 days ago

Self-Reporting Analysis

Of all the CVEs published by Salesforce, Inc. as a CNA, 33.3% affect products that Salesforce, Inc. develops as a vendor.

33.3%
66.7%
Self-reported: 15 (33.3%)
Third-party: 30 (66.7%)

Of all the CVEs published that affect products developed by Salesforce, Inc., 75.0% are self-published by Salesforce, Inc. as a CNA.

75.0%
25.0%
Self-published: 15 (75.0%)
Other CNAs: 5 (25.0%)

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22583CRITICAL
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services
Jan 24, 20269.834NONO
CVE-2026-22582CRITICAL
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services
Jan 24, 20269.834NONO
CVE-2026-22586CRITICAL
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Web
Jan 24, 20269.833NONO
CVE-2026-22584CRITICAL
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This i
Jan 9, 20269.833NONO
CVE-2026-22585CRITICAL
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub
Jan 24, 20269.831NONO
CVE-2023-26136CRITICAL
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode.
Jul 1, 20239.831NONO
CVE-2021-1628CRITICAL
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affect
Mar 26, 20219.830NONO
CVE-2021-1626CRITICAL
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions a
Mar 26, 20219.830NONO
CVE-2016-15012CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This issue affects the function Compu
Jan 7, 20239.829NONO
CVE-2021-1627CRITICAL
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This
Mar 26, 20219.829NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
40%
10%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (95.0%)
Unknown0 (0.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None20 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Salesforce, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Salesforce, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Salesforce, Inc.'s Products

View all 5 CNAs →

Top CWEs