Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Knowage MEDIUM 6.5
CVE-2025-58441

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerabil…

Fix: 8.1.37+
Fix from $1,600 2026-01-07
Knowage CRITICAL 9.8
CVE-2025-59954

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using a…

Fix: 8.1.27+
Fix from $2,300 2025-09-30
Knowage MEDIUM 5.3
CVE-2025-55007

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. T…

Fix: 8.1.37+
Fix from $1,600 2025-09-01
Spagobi CRITICAL 9.1
CVE-2024-54794EPSS 13%

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

No fix yet
Fix from $2,300 2025-01-21
Spagobi MEDIUM 6.1
CVE-2024-54792

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a…

No fix yet
Fix from $1,600 2025-01-21
Spagobi MEDIUM 5.4
CVE-2024-54795

SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

No fix yet
Fix from $1,600 2025-01-21
Knowage HIGH 8.8
CVE-2023-38702

Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/…

Fix: 8.1.8+
Fix from $1,950 2023-08-04
Knowage MEDIUM 6.5
CVE-2023-37472

Knowage is an open source suite for business analytics. The application often use user supplied data to create HQL queries without prior sanitization…

Fix: 8.1.8+
Fix from $1,600 2023-07-14
Knowage MEDIUM 6.5
CVE-2023-36819

Knowage is the professional open source suite for modern business analytics over traditional sources and big data systems. The endpoint `_/knowage/re…

Fix: 8.1.8+
Fix from $1,600 2023-07-03
Knowage MEDIUM 6.5
CVE-2023-35154

Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register a…

Fix: 8.1.8+
Fix from $1,600 2023-06-23
Knowage MEDIUM 6.1
CVE-2022-39295

Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x b…

Fix: 7.4.22 / 8.0.9+
Fix from $1,600 2022-10-13
Knowage MEDIUM 6.1
CVE-2021-30213

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/Ada…

No fix yet
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30211

Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signu…

Mitigation only
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30212

Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/docum…

No fix yet
Fix from $1,600 2021-05-12
Knowage MEDIUM 5.4
CVE-2021-30214EPSS 24%

Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.

No fix yet
Fix from $1,600 2021-05-12
Knowage HIGH 8.8
CVE-2021-30055

A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' paramete…

Fix: 7.4+
Fix from $1,950 2021-04-05
Knowage MEDIUM 6.1
CVE-2021-30058

Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/…

Fix: 7.4+
Fix from $1,600 2021-04-05
Knowage MEDIUM 5.4
CVE-2021-30056

Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publ…

Fix: 7.4+
Fix from $1,600 2021-04-05
Spagobi HIGH 8.8
CVE-2013-6231EPSS 10%

SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

Fix: 4.1+
Fix from $1,950 2020-01-10
Spagobi HIGH 8.0
CVE-2013-6234EPSS 7%

Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by…

Fix: 4.1+
Fix from $1,950 2019-11-22
Knowage CRITICAL 9.8
CVE-2019-13188

In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

Fix: 6.4+
Fix from $2,300 2019-09-05
Knowage MEDIUM 5.3
CVE-2019-13190

In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.

Fix: after 6.1.1
Fix from $1,600 2019-09-05
Knowage HIGH 8.8
CVE-2019-13348

In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which…

Fix: 6.4+
Fix from $1,950 2019-08-28
Knowage MEDIUM 6.1
CVE-2019-13189

In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.

Fix: 6.4+
Fix from $1,600 2019-08-28
Knowage MEDIUM 6.1
CVE-2018-12355

Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.

Mitigation only
Fix from $1,600 2018-06-13
Spagobi MEDIUM 6.8
CVE-2014-7296

The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated user…

Mitigation only
Fix from $1,600 2014-10-08