outsystems CVE Vulnerabilities & Metrics

Focus on outsystems vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About outsystems Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with outsystems. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total outsystems CVEs: 6
Earliest CVE date: 31 Dec 2019, 15:15 UTC
Latest CVE date: 09 Dec 2025, 18:15 UTC

Latest CVE reference: CVE-2025-61258

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical outsystems CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.33

Max CVSS: 6.4

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 4
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS outsystems CVEs

These are the five CVEs with the highest CVSS scores for outsystems, sorted by severity first and recency.

All CVEs for outsystems

CVE-2025-61258 outsystems vulnerability CVSS: 0 09 Dec 2025, 18:15 UTC

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this.

CVE-2022-47636 outsystems vulnerability CVSS: 0 10 Aug 2023, 16:15 UTC

A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.

CVE-2020-13639 outsystems vulnerability CVSS: 4.3 31 Aug 2021, 04:15 UTC

A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications. It could allow an unauthenticated remote attacker to craft and store malicious Feedback content into /ECT_Provider/, such that when the content is viewed (it can only be viewed by Administrators), attacker-controlled JavaScript will execute in the security context of an administrator's browser. This is fixed in Outsystems 10.0.1005.2, Outsystems 11.9.0 Platform Server, and Outsystems 11.7.0 LifeTime Management Console.

CVE-2021-29357 outsystems vulnerability CVSS: 5.0 12 Apr 2021, 19:15 UTC

The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.

CVE-2020-29441 outsystems vulnerability CVSS: 6.4 30 Nov 2020, 22:15 UTC

An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.

CVE-2019-12273 outsystems vulnerability CVSS: 4.3 31 Dec 2019, 15:15 UTC

OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability exists