mieweb has 5 CVEs on record. The median CVSS is 4.1 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- enterprise_health 5
Worst active — by depth score
CVE-2025-35030High· 8.1Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that admi…45CVE-2025-35034Medium· 4.3Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter24CVE-2025-35033Medium· 4.1Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files23CVE-2025-35032Low· 3.4Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files19CVE-2025-35031Low· 3.3Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output18
mieweb vulnerabilities
CVEs affecting mieweb, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-35034Medium· 4.3Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the …
CVE-2025-35033Medium· 4.1Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.
CVE-2025-35032Low· 3.4Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
CVE-2025-35031Low· 3.3Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This…
CVE-2025-35030High· 8.1Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that admi…
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that admi…