Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-15097

    Alteryx Server status improper authentication

    Last Modified: Apr 15, 2026
    Published: Dec 26, 2025

    CVE-2025-63291

    When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the specified MongoDB object ID. By specifying particlar MongoDB object IDs, callers could obtain records for other users without proper authorization. Records retrievable using this attack included administrative API keys and private studio api keys.

    Last Modified: Jan 12, 2026
    Published: Nov 14, 2025

    CVE-2025-28243

    An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.

    Last Modified: Jul 17, 2025
    Published: Jul 10, 2025

    CVE-2025-28244

    Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover

    Last Modified: Jul 17, 2025
    Published: Jul 10, 2025

    CVE-2025-28245

    Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body.

    Last Modified: Jul 17, 2025
    Published: Jul 10, 2025
    Items Per Page
    Alteryx Vulnerabilities & Security CVEs | CVE-DB