Eng / Knowage
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-58441 | Knowage is vulnerable to blind server-side request forgery (SSRF) | MEDIUM | 6.3 | Jan 7, 2026 |
| CVE-2025-59954 | Knowage Contains a Remote Code Execution Vulnerability | CRITICAL | 9.3 | Sep 29, 2025 |
| CVE-2025-55007 | Knowage vulnerable to server-side request forgery | MEDIUM | 5.3 | Sep 1, 2025 |
| CVE-2024-57971 | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning… | CRITICAL | 9.1 | Feb 16, 2025 |
| CVE-2023-38702 | Knowage Server vulnerable to path traversal via upload functionality | CRITICAL | 10.0 | Aug 4, 2023 |
| CVE-2023-37472 | Query injection in Knowage server | HIGH | 7.7 | Jul 14, 2023 |
| CVE-2023-36819 | Knowage-Server vulnerable to Path traversal in download functionalities | MEDIUM | 6.5 | Jul 3, 2023 |
| CVE-2023-35154 | Knowage-Server vulnerable to account validation bypass | HIGH | 7.2 | Jun 23, 2023 |
| CVE-2022-39295 | Improper Neutralization of Alternate XSS Syntax in Knowage-Server | MEDIUM | 6.1 | Oct 13, 2022 |
| CVE-2021-30213 | Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP'… | MEDIUM | 6.1 | May 12, 2021 |
| CVE-2021-30214 | Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter. | MEDIUM | 5.4 | May 12, 2021 |
| CVE-2021-30212 | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/s… | MEDIUM | 5.4 | May 12, 2021 |
| CVE-2021-30211 | Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update'… | MEDIUM | 5.4 | May 12, 2021 |
| CVE-2021-30055 | A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when run… | HIGH | 8.8 | Apr 5, 2021 |
| CVE-2021-30056 | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via th… | MEDIUM | 5.4 | Apr 5, 2021 |
| CVE-2021-30057 | A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" v… | MEDIUM | 4.8 | Apr 5, 2021 |
| CVE-2021-30058 | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/… | MEDIUM | 6.1 | Apr 5, 2021 |
| CVE-2019-13188 | In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. | CRITICAL | 9.8 | Sep 5, 2019 |
| CVE-2019-13190 | In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page. | MEDIUM | 5.3 | Sep 5, 2019 |
| CVE-2019-13348 | In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes… | HIGH | 8.8 | Aug 28, 2019 |
| CVE-2019-13189 | In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page. | MEDIUM | 6.1 | Aug 28, 2019 |
| CVE-2018-12355 | Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue. | MEDIUM | 6.1 | Jun 13, 2018 |
Showing 1 to 21 of 21 CVEs