Splunk Cloud Platform
Vendor:
First CVE: Jun 15, 2022 · Active for 4 years
109
Total CVEs
More Total CVEs than 99% of tracked products
21.8
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Splunk Cloud Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2022
4 years ago
Most Recent CVE
Jul 15, 2026
10 days ago
CVE Severity & Scoring
Splunk Cloud Platform109 CVEs
63%
31%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.9%)
Network107 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low102 (93.6%)
High7 (6.4%)
Unknown0 (0.0%)
User Interaction
None60 (55.0%)
Unknown0 (0.0%)
Required49 (45.0%)
Privileges Required
Low74 (67.9%)
High11 (10.1%)
None24 (22.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (109 CVEs).
109 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32707HIGH In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_us | Jun 1, 2023 | 8.8 | 85 | NO | YES |
CVE-2022-43571HIGH In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
| Nov 3, 2022 | 8.8 | 48 | NO | YES |
CVE-2026-20251HIGH In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk | Jun 10, 2026 | 8.8 | 47 | NO | NO |
CVE-2022-43568MEDIUM In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when out | Nov 4, 2022 | 6.1 | 43 | NO | NO |
CVE-2026-20296HIGH In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507 | Jul 15, 2026 | 8.3 | 39 | NO | NO |
CVE-2026-20297HIGH In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.2.2510.18, and 10.1.2507.24, a | Jul 15, 2026 | 7.2 | 34 | NO | NO |
CVE-2026-20239HIGH In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that h | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2025-20229HIGH In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged | Mar 26, 2025 | 8.0 | 33 | NO | NO |
CVE-2026-20298MEDIUM In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507 | Jul 15, 2026 | 6.5 | 32 | NO | NO |
CVE-2025-20371HIGH In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacke | Oct 1, 2025 | 8.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (109 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (109 CVEs).
Media Mentions
Signals from CVEs in this product scope (109 CVEs).
Top CNAs Publishing CVEs For Splunk Cloud Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.4.2603 | 1 | 6.5 | 0.4% | 0 | 0 |
| 10.1.2507 | 1 | 5.7 | 0.2% | 0 | 0 |