Tableau Server
Tableau · 23 CVEs
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source…
Aug 22, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serv…
Aug 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish…
Aug 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Edit…
Aug 22, 2025
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Deskt…
Aug 22, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) al…
Jul 25, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector mo…
Jul 25, 2025
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modul…
Jul 25, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serv…
Jul 25, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensibl…
Jul 25, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate…
Jul 25, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-init…
Jul 25, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc…
Jul 25, 2025
Sensitive Data Exposure in Tableau Server
Feb 11, 2025
Server Side Request Forgery vulnerability in Tableau Server
Feb 11, 2025
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfe…
Oct 17, 2022
Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers…
May 25, 2022
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
Mar 26, 2021
Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated user…
Nov 23, 2020
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26…
Jul 8, 2020
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
Dec 11, 2019
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informa…
Aug 26, 2019
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated use…
Jan 31, 2014
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-52451 | Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolu… | HIGH | 0.21% | Aug 22, 2025 |
| CVE-2025-52450 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create… | MEDIUM | 0.43% | Aug 22, 2025 |
| CVE-2025-26498 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Abso… | HIGH | 0.27% | Aug 22, 2025 |
| CVE-2025-26497 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Travers… | HIGH | 0.27% | Aug 22, 2025 |
| CVE-2025-26496 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload module… | CRITICAL | 0.21% | Aug 22, 2025 |
| CVE-2025-52455 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This is… | MEDIUM | 0.34% | Jul 25, 2025 |
| CVE-2025-52454 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing… | HIGH | 0.30% | Jul 25, 2025 |
| CVE-2025-52453 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. T… | HIGH | 0.30% | Jul 25, 2025 |
| CVE-2025-52452 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - dupli… | HIGH | 0.44% | Jul 25, 2025 |
| CVE-2025-52449 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alter… | HIGH | 0.26% | Jul 25, 2025 |
| CVE-2025-52448 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interfa… | HIGH | 0.36% | Jul 25, 2025 |
| CVE-2025-52447 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows I… | HIGH | 0.36% | Jul 25, 2025 |
| CVE-2025-52446 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulati… | HIGH | 0.24% | Jul 25, 2025 |
| CVE-2025-26495 | Sensitive Data Exposure in Tableau Server | HIGH | 0.34% | Feb 11, 2025 |
| CVE-2025-26494 | Server Side Request Forgery vulnerability in Tableau Server | HIGH | 0.57% | Feb 11, 2025 |
| CVE-2022-22128 | Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code e… | CRITICAL | 1.51% | Oct 17, 2022 |
| CVE-2022-22127 | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity Store for managing… | HIGH | 1.09% | May 25, 2022 |
| CVE-2021-1629 | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users. | MEDIUM | 1.34% | Mar 26, 2021 |
| CVE-2020-6939 | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users. If exploited, this could allow a mali… | CRITICAL | 1.83% | Nov 23, 2020 |
| CVE-2020-6938 | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to sensitive… | HIGH | 1.22% | Jul 8, 2020 |
| CVE-2019-19719 | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. | MEDIUM | 22.04% | Dec 11, 2019 |
| CVE-2019-15637 | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects T… | HIGH | 14.31% | Aug 26, 2019 |
| CVE-2014-1204 | SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via… | HIGH | 4.18% | Jan 31, 2014 |
Showing 1 to 23 of 23 CVEs