Sonarqube
Sonarsource · 7 CVEs
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2…
Oct 10, 2025
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memb…
Oct 4, 2024
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Admin…
Oct 4, 2024
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentiall…
Jun 16, 2024
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty va…
Oct 30, 2020
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/setti…
Oct 28, 2020
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
Oct 14, 2019
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive…
Dec 14, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-62292 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obt… | MEDIUM | 0.22% | Oct 10, 2025 |
| CVE-2024-47911 | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQu… | HIGH | 0.45% | Oct 4, 2024 |
| CVE-2024-47910 | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing con… | HIGH | 0.48% | Oct 4, 2024 |
| CVE-2024-38460 | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the UR… | MEDIUM | 0.33% | Jun 16, 2024 |
| CVE-2020-28002 | In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anony… | MEDIUM | 1.07% | Oct 30, 2020 |
| CVE-2020-27986 | SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the ve… | HIGH | 15.97% | Oct 28, 2020 |
| CVE-2019-17579 | SonarSource SonarQube before 7.8 has XSS in project links on account/projects. | MEDIUM | 0.66% | Oct 14, 2019 |
| CVE-2018-19413 | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account l… | MEDIUM | 1.15% | Dec 14, 2018 |
Showing 1 to 7 of 7 CVEs