Dataease / SQLBot
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-93660 | SQLBot through 1.10.1 Improper Access Control via Dashboard Update | HIGH | 7.1 | Sep 18, 2026 |
| CVE-2026-53557 | SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution | HIGH | 7.7 | Sep 17, 2026 |
| CVE-2026-53555 | Stored XSS via SVG Upload | MEDIUM | 5.1 | Sep 17, 2026 |
| CVE-2026-53556 | SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read | MEDIUM | 6.0 | Sep 17, 2026 |
| CVE-2026-53554 | SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing | HIGH | 7.3 | Sep 17, 2026 |
| CVE-2026-72743 | SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html | MEDIUM | 5.1 | Aug 10, 2026 |
| CVE-2026-42463 | SQLBot: Unauthorized Access Vulnerability | HIGH | 8.6 | May 13, 2026 |
| CVE-2026-33324 | SQLBot prompt injection allows arbitrary SQL execution and remote code execution | CRITICAL | 9.4 | May 5, 2026 |
| CVE-2026-5417 | Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery | MEDIUM | 5.1 | Apr 2, 2026 |
| CVE-2026-32950 | SQLBot: RCE via SQL Injection in Excel Upload Endpoint | HIGH | 8.6 | Mar 20, 2026 |
| CVE-2026-32949 | SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL | HIGH | 8.7 | Mar 20, 2026 |
| CVE-2026-32622 | SQLBot: Remote Code Execution via Terminology Poisoning | HIGH | 8.6 | Mar 19, 2026 |
| CVE-2025-15598 | Dataease SQLBot JWT Token auth.py validateEmbedded signature verification | MEDIUM | 6.3 | Mar 3, 2026 |
| CVE-2025-15597 | Dataease SQLBot API Endpoint assistant.py access control | MEDIUM | 5.3 | Mar 2, 2026 |
| CVE-2025-69285 | SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability | HIGH | 7.7 | Jan 21, 2026 |
Showing 1 to 14 of 14 CVEs