Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Uipath

First CVE: Apr 11, 2019Active for: 7 yearsTotal CVEs: 6

UiPath's vulnerability profile centers on its robotic process automation platform, which spans orchestration, automation studio, and process assistant components widely deployed in enterprise workflow environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward confirmed in-the-wild exploitation; the recurring weakness classes—including embedded malicious code, external resource reference, output escaping failures, and cross-site scripting—reflect both the integration-heavy nature of RPA tooling and the web-facing automation interfaces that sit in sensitive business process paths. Defenders should prioritize UiPath advisories and treat exposed orchestrator and studio instances as high-value remediation targets; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
16.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Uipath over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2019
7 years ago
Most Recent CVE
May 12, 2026
73 days ago

Products(69 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-45321CRITICAL
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated
May 12, 20269.679YESNO
CVE-2021-44041CRITICAL
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This all
Dec 14, 20219.830NONO
CVE-2021-44042CRITICAL
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encode
Dec 14, 20219.829NONO
CVE-2018-17305HIGH
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote cod
Apr 11, 20198.828NONO
CVE-2021-44043MEDIUM
An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps
Dec 14, 20215.419NONO
CVE-2018-19855MEDIUM
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.
Aug 8, 20195.519NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
17%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
1 CVE
16.7% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Uipath.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Uipath — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Uipath's Products

View all 2 CNAs →

Top CWEs