Wolterskluwer is a professional software and services vendor whose vulnerability footprint concentrates in a small set of business-process and workflow applications, including invoicing, payment, and audit-management platforms. The recurring weakness classes in these disclosures cluster around input-handling and output-encoding flaws—cross-site scripting, injection, and SQL injection—that are characteristic of web-facing business applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wolterskluwer over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3125HIGH Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct | Aug 26, 2010 | 9.3 | 39 | NO | YES |
CVE-2021-41932HIGH A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in comple | Jun 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-44035HIGH Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files. | Dec 17, 2021 | 7.8 | 25 | NO | NO |
CVE-2026-1493MEDIUM LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely
processes the parameter on the client side, allowing an attacker to execute ar | Apr 30, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-2680MEDIUM Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, whi | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-2679MEDIUM Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could a | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-2678MEDIUM Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which c | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-2677MEDIUM Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which co | Feb 26, 2026 | 6.1 | 22 | NO | NO |
CVE-2023-49328HIGH On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injec | Dec 25, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-33438MEDIUM A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML. | Jun 16, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wolterskluwer.
Media articles that mention a CVE ID that affects a product developed by Wolterskluwer — matched by CVE ID, not by vendor name.