VYPR

SAPUI5

by SAP

CVEs (7)

  • CVE-2023-30743HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the…

  • CVE-2026-66771MedAug 11, 2026
    risk 0.40cvss 6.1epss 0.00

    SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation…

  • CVE-2019-0281MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2025-42873MedDec 9, 2025
    risk 0.38cvss 5.9epss 0.00

    SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage…

  • CVE-2019-0388MedNov 13, 2019
    risk 0.35cvss 5.3epss 0.01

    SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

  • CVE-2026-34258MedMay 12, 2026
    risk 0.31cvss 4.7epss 0.00

    SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicking and accessing attacker-controlled pages rendered by the application. This…

  • CVE-2025-42990LowJun 10, 2025
    risk 0.20cvss 3.0epss 0.00

    Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are…