VendorsSparxsystemsenterprise_architectall versions
Vulnerabilities

Sparxsystems Enterprise Architect

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-47072
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..
Published 2024-01-31 · Modified
9.8EPSS 0.006
CVE-2025-15621
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
Published 2026-04-16 · Analyzed
6.0EPSS 0.001