Salesforce records
21 published records for vendor salesforce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 76.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-26136Proof of concept | Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cookisalesforce · tough-cookie · CWE-1321 | Critical9.8 | — | 2.5% | Jul 1, 2023 |
40Plan | CVE-2021-1626No exploit | MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloudsalesforce · mule | Critical9.8 | — | 2.0% | Mar 26, 2021 |
39Monitor | CVE-2021-1628No exploit | MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both Csalesforce · mule · CWE-611 | Critical9.8 | — | 1.2% | Mar 26, 2021 |
39Monitor | CVE-2021-1627No exploit | MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect bothsalesforce · mule · CWE-918 | Critical9.8 | — | 1.0% | Mar 26, 2021 |
39Monitor | CVE-2026-22583No exploit | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (Csalesforce · marketing cloud engagement · CWE-88 | Critical9.8 | — | 0.7% | Jan 23, 2026 |
39Monitor | CVE-2026-22582No exploit | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (Msalesforce · marketing cloud engagement · CWE-88 | Critical9.8 | — | 0.7% | Jan 23, 2026 |
39Monitor | CVE-2016-15012No exploit | forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injectionsalesforce · mobile software development kit · CWE-89 | Critical9.8 | — | 0.7% | Jan 7, 2023 |
39Monitor | CVE-2026-22586No exploit | Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscrsalesforce · marketing cloud engagement · CWE-321 | Critical9.8 | — | 0.6% | Jan 23, 2026 |
39Monitor | CVE-2026-22585No exploit | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Prsalesforce · marketing cloud engagement · CWE-327 | Critical9.8 | — | 0.4% | Jan 23, 2026 |
39Monitor | CVE-2026-22584No exploit | Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executsalesforce · uni2ts · CWE-94 | Critical9.8 | — | 0.4% | Jan 9, 2026 |
32Monitor | CVE-2024-39344No exploit | An issue was discovered in the Docusign API package 8.142.14 for Salesforce.CWE-200 | High8.1 | — | 0.5% | Aug 21, 2024 |
31Monitor | CVE-2017-15010No exploit | A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.salesforce · tough-cookie · CWE-400 | High7.5 | — | 3.3% | Oct 3, 2017 |
30Monitor | CVE-2021-1630No exploit | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fsalesforce · mule · CWE-611 | High7.5 | — | 1.1% | Aug 5, 2021 |
26Monitor | CVE-2025-64320No exploit | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issalesforce · agentforce vibes · CWE-94 | Medium6.5 | — | 0.2% | Nov 4, 2025 |
26Monitor | CVE-2025-10875No exploit | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thisalesforce · mulesoft anypoint code builder · CWE-94 | Medium6.5 | — | 0.2% | Nov 4, 2025 |
22Monitor | CVE-2016-1000232No exploit | NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result salesforce · tough-cookie · CWE-20 | Medium5.3 | — | 2.4% | Sep 5, 2018 |
21Monitor | CVE-2025-64318No exploit | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writesalesforce · mulesoft anypoint code builder · CWE-94 | Medium5.3 | — | 0.2% | Nov 4, 2025 |
21Monitor | CVE-2025-64321No exploit | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeablesalesforce · agentforce vibes · CWE-94 | Medium5.3 | — | 0.2% | Nov 4, 2025 |
21Monitor | CVE-2025-64322No exploit | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Csalesforce · agentforce vibes · CWE-732 | Medium5.3 | — | 0.2% | Nov 4, 2025 |
21Monitor | CVE-2025-64319No exploit | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeabsalesforce · mulesoft anypoint code builder · CWE-732 | Medium5.3 | — | 0.2% | Nov 4, 2025 |
20Monitor | CVE-2026-34951No exploit | Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessionssalesforce · workbench · CWE-79 | Medium5.1 | — | 0.3% | Apr 6, 2026 |
- CVE-2023-2613640Plan
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cooki
CriticalCVSS 9.8Proof of conceptEPSS 3%salesforce · tough-cookieJul 1, 2023
- CVE-2021-162640Plan
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both Cloud
CriticalCVSS 9.8No exploitEPSS 2%salesforce · muleMar 26, 2021
- CVE-2021-162839Monitor
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both C
CriticalCVSS 9.8No exploitEPSS 1%salesforce · muleMar 26, 2021
- CVE-2021-162739Monitor
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both
CriticalCVSS 9.8No exploitEPSS 1%salesforce · muleMar 26, 2021
- CVE-2026-2258339Monitor
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (C
CriticalCVSS 9.8No exploitEPSS 1%salesforce · marketing cloud engagementJan 23, 2026
- CVE-2026-2258239Monitor
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (M
CriticalCVSS 9.8No exploitEPSS 1%salesforce · marketing cloud engagementJan 23, 2026
- CVE-2016-1501239Monitor
forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injection
CriticalCVSS 9.8No exploitEPSS 1%salesforce · mobile software development kitJan 7, 2023
- CVE-2026-2258639Monitor
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscr
CriticalCVSS 9.8No exploitEPSS 1%salesforce · marketing cloud engagementJan 23, 2026
- CVE-2026-2258539Monitor
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr
CriticalCVSS 9.8No exploitEPSS 0%salesforce · marketing cloud engagementJan 23, 2026
- CVE-2026-2258439Monitor
Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Execut
CriticalCVSS 9.8No exploitEPSS 0%salesforce · uni2tsJan 9, 2026
- CVE-2024-3934432Monitor
An issue was discovered in the Docusign API package 8.142.14 for Salesforce.
HighCVSS 8.1No exploitEPSS 1%Aug 21, 2024
- CVE-2017-1501031Monitor
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.
HighCVSS 7.5No exploitEPSS 3%salesforce · tough-cookieOct 3, 2017
- CVE-2021-163030Monitor
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime F
HighCVSS 7.5No exploitEPSS 1%salesforce · muleAug 5, 2021
- CVE-2025-6432026Monitor
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This is
MediumCVSS 6.5No exploitEPSS 0%salesforce · agentforce vibesNov 4, 2025
- CVE-2025-1087526Monitor
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.Thi
MediumCVSS 6.5No exploitEPSS 0%salesforce · mulesoft anypoint code builderNov 4, 2025
- CVE-2016-100023222Monitor
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result
MediumCVSS 5.3No exploitEPSS 2%salesforce · tough-cookieSep 5, 2018
- CVE-2025-6431821Monitor
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Write
MediumCVSS 5.3No exploitEPSS 0%salesforce · mulesoft anypoint code builderNov 4, 2025
- CVE-2025-6432121Monitor
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable
MediumCVSS 5.3No exploitEPSS 0%salesforce · agentforce vibesNov 4, 2025
- CVE-2025-6432221Monitor
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable C
MediumCVSS 5.3No exploitEPSS 0%salesforce · agentforce vibesNov 4, 2025
- CVE-2025-6431921Monitor
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeab
MediumCVSS 5.3No exploitEPSS 0%salesforce · mulesoft anypoint code builderNov 4, 2025
- CVE-2026-3495120Monitor
Reflected XSS in footer.php in Workbench Allows Attackers to Hijack Authenticated Sessions
MediumCVSS 5.1No exploitEPSS 0%salesforce · workbenchApr 6, 2026