Microstrategy

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 20
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    14
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-22983

    A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

    Last Modified: Jul 04, 2026
    Published: May 13, 2022

    CVE-2020-22985

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

    Last Modified: Jul 04, 2026
    Published: May 12, 2022

    CVE-2020-22986

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

    Last Modified: Jul 04, 2026
    Published: May 12, 2022

    CVE-2020-22987

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

    Last Modified: Jul 05, 2026
    Published: May 12, 2022

    CVE-2020-22984

    Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

    Last Modified: Jul 04, 2026
    Published: May 12, 2022
    Items Per Page