wolterskluwer CVE Vulnerabilities & Metrics

Focus on wolterskluwer vulnerabilities and metrics.

Last updated: 08 Mar 2026, 23:25 UTC

About wolterskluwer Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with wolterskluwer. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total wolterskluwer CVEs: 8
Earliest CVE date: 26 Aug 2010, 18:36 UTC
Latest CVE date: 26 Feb 2026, 13:16 UTC

Latest CVE reference: CVE-2026-2680

Rolling Stats

30-day Count (Rolling): 4
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical wolterskluwer CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.51

Max CVSS: 9.3

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 2
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS wolterskluwer CVEs

These are the five CVEs with the highest CVSS scores for wolterskluwer, sorted by severity first and recency.

All CVEs for wolterskluwer

CVE-2026-2680 wolterskluwer vulnerability CVSS: 0 26 Feb 2026, 13:16 UTC

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVE-2026-2679 wolterskluwer vulnerability CVSS: 0 26 Feb 2026, 13:16 UTC

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVE-2026-2678 wolterskluwer vulnerability CVSS: 0 26 Feb 2026, 13:16 UTC

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVE-2026-2677 wolterskluwer vulnerability CVSS: 0 26 Feb 2026, 13:16 UTC

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVE-2023-49328 wolterskluwer vulnerability CVSS: 0 25 Dec 2023, 06:15 UTC

On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.

CVE-2023-33438 wolterskluwer vulnerability CVSS: 0 16 Jun 2023, 21:15 UTC

A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.

CVE-2021-41932 wolterskluwer vulnerability CVSS: 6.5 06 Jun 2022, 15:15 UTC

A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc.

CVE-2021-44035 wolterskluwer vulnerability CVSS: 6.8 17 Dec 2021, 16:15 UTC

Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.

CVE-2010-3125 wolterskluwer vulnerability CVSS: 9.3 26 Aug 2010, 18:36 UTC

Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .tmx file.