Fiori Launchpad
4 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Fiori Launchpad, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Fiori Launchpad CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 4 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium4
Latest CVEs
The 4 most recently published vulnerabilities affecting Fiori Launchpad.
- CVE-2023-49584Client-Side Desynchronization vulnerability in SAP Fiori Launchpad4.3
- CVE-2022-26101Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.6.1
- CVE-2020-6283SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in ...6.1
- CVE-2020-6210SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable par...6.1
Product grouping is registry-driven, with AI assist and human review. How it works