CVE-2023-23835: Mendix

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors.

Affected products

  • Mendix Mendix: from 7.0.2, before 7.23.34 (fixed in 7.23.34); from 8.0.0, before 8.18.23 (fixed in 8.18.23); from 9.0.0, before 9.6.15 (fixed in 9.6.15); from 9.7.0, before 9.12.10 (fixed in 9.12.10); from 9.18.0, before 9.18.4 (fixed in 9.18.4); from 9.19.0, before 9.22.0 (fixed in 9.22.0)

Published 2023-02-14. Last modified 2026-06-17.