Overview
This article lists the vulnerabilities (CVEs) reported on third-party libraries and components used by Wiiisdom Cloud Platform (including Wiiisdom for Power BI), whether the platform was affected, and the remediation. The list is sorted from the most recent CVE to the oldest.

Wiiisdom Cloud Platform is a SaaS platform operated by Wiiisdom: security fixes are deployed by our team and no action is required on your side. Releases before 2026 used internal 1.x version numbers; the dates and public release names are given instead.
Legend
- Not affected: the vulnerable code or feature is not used, not reachable or not configured in the product.
- Low risk: the bundled component is in the affected range, but exploitation requires a non-default configuration or local access. It has been (or will be) upgraded anyway.
- Affected – fixed: the product shipped an affected version of the component. The fixed product version is given in the details.
- Not applicable: the component is not part of the product (for example, it belongs to a third-party platform installed on the same server).
Reported CVEs
| CVE | Component | Impact | Details & remediation |
|---|---|---|---|
| 2026 | |||
| CVE-2026-50559 | Quarkus | Affected – fixed | Quarkus upgraded to 3.33.2.1 in release 2026.7.0. |
| CVE-2026-33117 | Azure SDK for Java (Key Vault Keys 4.10.2) | Affected – fixed | Critical. Library upgraded to 4.10.6 in release 2026.6.1 (June 2026). |
| CVE-2026-4634 CVE-2026-4282 | Third-party dependency | Affected – fixed | Fixed in security hotfix 2026.4.1 (April 2026). |
| CVE-2026-3009 | Keycloak (identity provider management) | Affected – fixed | Keycloak upgraded to 26.5.5 in security hotfix 2026.3.1. |
| CVE-2026-2603 | Keycloak | Affected – fixed | Keycloak upgraded in release 2026.4.0. |
| 2025 | |||
| Quarkus security advisories | Quarkus / Keycloak | Affected – fixed | Quarkus upgraded to the 3.20 LTS line (2025.3), then to 3.20.2.1 with Keycloak 26.3.3 (2025.3.3, August 2025). The February 2025 Quarkus CVE fixes were applied in 2025.2 (April 2025). |
| 2024 | |||
| CVE-2024-39338 | axios | Affected – fixed | axios upgraded to 1.7.4 in August 2024 (2024.3). |
| CVE-2024-35255 | Azure Identity SDK | Low risk | Medium severity; exploitation requires access to the container. SDK updated in July 2024 (2024.3). |
| CVE-2024-8698 | Keycloak 25.0.x (SAML) | Affected – fixed | Affected the SAML login implementation. Keycloak upgraded to 25.0.6 in September 2024 (2024.3 hotfix, then 2024.4). |
| CVE-2024-7341 | Keycloak 25.0.1 | Affected – fixed | Keycloak upgraded to 25.0.5 in September 2024 (2024.3 hotfix). |
| CVE-2024-2419 CVE-2024-1132 | Keycloak < 24.0.3 | Low risk | Our penetration tests could not exploit these vulnerabilities, with or without the Web Application Firewall. Keycloak upgraded to 24.0.3 in May 2024 (2024.2). |
| 2022 | |||
| CVE-2022-4147 CVE-2022-4116 | Quarkus 2.x | Affected – fixed | Quarkus upgraded in January 2024 (2024.1). |
| CVE-2022-1471 | SnakeYAML | Not affected | YAML parsing is not used (Liquibase uses XML changelogs, Jackson YAML is only used at build time). |
Other security events
- November 2025 – Shai-Hulud 2.0 npm supply-chain attack: not affected. No compromised package was found in any Wiiisdom Cloud Platform component. Dependency installation has since been restricted to locked versions only.
Your CVE is not listed?
This page lists the vulnerabilities that were reported to us or analysed by our teams. It is not an exhaustive list of every CVE fixed by a component upgrade: check the Security section of the release notes for the complete list.
If your security scanner reports a CVE that is not listed here, open a ticket with the Support team and include the CVE ID, the product version, and the exact file or path flagged by the scanner. We will analyse it and add it to this page.