CVE-2021-36761
CVE-2021-36761 is a medium-severity vulnerability in Qlik Qlik Sense with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-918.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- EPSS exploit prediction: 1% (65th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-918
- Affected product: Qlik Qlik Sense
- Published:
- Last modified:
Description
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
Frequently asked questions
- What is CVE-2021-36761?
- The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
- How severe is CVE-2021-36761?
- CVE-2021-36761 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2021-36761 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (65th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-36761?
- CVE-2021-36761 affects Qlik Qlik Sense. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-36761?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-36761 published?
- CVE-2021-36761 was published on 2022-06-21 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:qlik:qlik_sense:april_2020:patch4:*:*:*:*:*:*
More vulnerabilities in Qlik Qlik Sense
- CVE-2023-48365 — Critical (CVSS 9.6): Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka…
- CVE-2023-41265 — Critical (CVSS 9.6): An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and…
- CVE-2023-41266 — High (CVSS 8.2): A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier,…
- CVE-2019-11628 — High (CVSS 8.2): An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and…
- CVE-2025-61138 — High (CVSS 7.5): Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
- CVE-2022-0564 — Medium (CVSS 5.3): A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts.…
All CVEs affecting Qlik Qlik Sense →
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
- CVE-2026-57106 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-15409 — Critical (CVSS 10.0): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →