Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …
Metabase
0.58.24 / 0.59.21+
CRITICAL 9.1
CVE-2026-50148
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10,…
Metabase
1.54.24 / 1.55.24+
HIGH 7.6
CVE-2026-50147
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacke…
Metabase
1.57.19.1 / 1.58.14.1+
CRITICAL 9.1
CVE-2026-59826
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di…
Metabase
1.58.15.1 / 1.59.12+
HIGH 8.8
CVE-2026-59827
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances w…
Metabase
0.58.15 / 0.59.12+
HIGH 7.2
CVE-2026-33725
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.5…
Metabase
1.54.22 / 1.55.22+
MEDIUM 6.5
CVE-2026-27464
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to …
Metabase
0.57.13 / 0.58.7+
HIGH 8.6
CVE-2026-22805
Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscri…
Metabase
0.55.13 / 0.56.3+
HIGH 7.5
CVE-2025-5895
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/m…
Metabase
Patch available
MEDIUM 6.5
CVE-2025-27141
Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and p…
Metabase
1.50.36 / 1.51.14+
CRITICAL 9.8
CVE-2023-37470
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3…
Metabase
0.43.7.3 / 0.44.7.3+
CRITICAL 9.8
CVE-2023-38646EPSS 99%
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the serv…
Metabase
0.43.7.2 / 0.44.7.1+
CRITICAL 9.6
CVE-2023-32680
Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with nat…
Metabase
0.44.7 / 0.45.4+
MEDIUM 6.3
CVE-2023-23629
Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashbo…
Metabase
0.43.7.1 / 0.44.6.1+
HIGH 8.8
CVE-2022-39362
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries ar…
Metabase
0.41.9 / 0.42.6+
HIGH 8.8
CVE-2022-39361
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) c…
Metabase
0.41.9 / 0.42.6+
MEDIUM 6.5
CVE-2022-39360
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) us…
Metabase
0.41.9 / 0.42.6+
MEDIUM 6.5
CVE-2022-39359
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL…
Metabase
0.41.9 / 0.42.6+
MEDIUM 6.5
CVE-2022-39358
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked p…
Metabase
0.42.6 / 0.43.7+
MEDIUM 6.5
CVE-2022-43776
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously impl…
Metabase
0.44.5+
HIGH 8.8
CVE-2022-24854
Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows con…
Metabase
0.41.7 / 0.42.4+
MEDIUM 5.4
CVE-2022-24855
Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint…
Metabase
0.40.8 / 0.41.7+
MEDIUM 5.3
CVE-2022-24853
Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our …
Metabase
0.40.8 / 0.41.7+
HIGH 7.5
CVE-2021-41277 KEVEPSS 97%
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se…
Metabase
Patch available
MEDIUM 6.1
CVE-2018-0697
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecif…
Metabase
after 0.29.3