Apache / Superset
70 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-23985 | Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser | MEDIUM | 5.3 | Jul 30, 2026 |
| CVE-2026-23981 | Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification | MEDIUM | 5.3 | Jul 30, 2026 |
| CVE-2026-23969 | Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering | MEDIUM | 5.3 | Feb 24, 2026 |
| CVE-2026-23980 | Apache Superset: Improper Neutralization of Special Elements used in a SQL Command | MEDIUM | 5.3 | Feb 24, 2026 |
| CVE-2026-23982 | Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass | HIGH | 7.1 | Feb 24, 2026 |
| CVE-2026-23983 | Apache Superset: Sensitive Data Exposure via REST API (disabled by default) | LOW | 2.3 | Feb 24, 2026 |
| CVE-2026-23984 | Apache Superset: SQLLab Read-Only Bypass on PostgreSQL | HIGH | 7.1 | Feb 24, 2026 |
| CVE-2025-55675 | Apache Superset: Incorrect datasource authorization on REST API | MEDIUM | 5.3 | Aug 14, 2025 |
| CVE-2025-55674 | Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions | MEDIUM | 5.3 | Aug 14, 2025 |
| CVE-2025-55672 | Apache Superset: Stored XSS on charts metadata | MEDIUM | 5.3 | Aug 14, 2025 |
| CVE-2025-55673 | Apache Superset: Metadata exposure in embedded charts | MEDIUM | 5.3 | Aug 14, 2025 |
| CVE-2025-48912 | Apache Superset: Improper authorization bypass on row level security via SQL Injection | HIGH | 7.1 | May 30, 2025 |
| CVE-2025-27696 | Apache Superset: Incorrect authorization leading to resource ownership takeover | MEDIUM | 5.3 | May 13, 2025 |
| CVE-2024-55633 | Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access | HIGH | 7.1 | Dec 12, 2024 |
| CVE-2024-53949 | Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled | HIGH | 7.6 | Dec 9, 2024 |
| CVE-2024-53948 | Apache Superset: Error verbosity exposes metadata in analytics databases | MEDIUM | 5.3 | Dec 9, 2024 |
| CVE-2024-53947 | Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions | LOW | 2.3 | Dec 9, 2024 |
| CVE-2024-39887 | Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions | MEDIUM | 6.9 | Jul 16, 2024 |
| CVE-2024-34693 | Apache Superset: Server arbitrary file read | MEDIUM | 4.6 | Jun 20, 2024 |
| CVE-2024-28148 | Apache Superset: Incorrect datasource authorization on explore REST API | MEDIUM | 4.3 | May 7, 2024 |
| CVE-2024-26016 | Apache Superset: Improper authorization validation on dashboards and charts import | MEDIUM | 5.4 | Feb 28, 2024 |
| CVE-2024-24779 | Apache Superset: Improper data authorization when creating a new dataset | MEDIUM | 6.5 | Feb 28, 2024 |
| CVE-2024-24772 | Apache Superset: Improper Neutralisation of custom SQL on embedded context | MEDIUM | 4.3 | Feb 28, 2024 |
| CVE-2024-24773 | Apache Superset: Improper validation of SQL statements allows for unauthorized access to data | MEDIUM | 6.5 | Feb 28, 2024 |
| CVE-2024-27315 | Apache Superset: Improper error handling on alerts | MEDIUM | 5.3 | Feb 28, 2024 |
Showing 1 to 25 of 70 CVEs