VYPR

Dataease

by Dataease

Source repositories

CVEs (97)

  • CVE-2026-32939HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without specifying an explicit Locale,…

  • CVE-2023-32310HigJun 1, 2023
    risk 0.46cvss 8.1epss 0.01

    DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or…

  • CVE-2025-27103MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been…

  • CVE-2025-24974MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are…

  • CVE-2023-35168MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.01

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5…

  • CVE-2023-28435MedMar 24, 2023
    risk 0.42cvss 6.5epss 0.00

    Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These…

  • CVE-2023-35164MedJun 26, 2023
    risk 0.41cvss 6.3epss 0.00

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been…

  • CVE-2024-30269MedApr 8, 2024
    risk 0.39cvss 5.3epss 0.16

    DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned.…

  • CVE-2026-40899MedApr 16, 2026
    risk 0.35cvss 6.5epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter…

  • CVE-2025-62421MedOct 17, 2025
    risk 0.35cvss 5.4epss 0.00

    DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation and authentication bypass. The StaticResourceApi interface defines a route upload/{fileId}…

  • CVE-2023-37257MedJul 25, 2023
    risk 0.35cvss 5.4epss 0.00

    DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

  • CVE-2022-34112MedJul 22, 2022
    risk 0.35cvss 6.5epss 0.01

    An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.

  • CVE-2026-82879MedAug 31, 2026
    risk 0.34cvss 6.3epss 0.00

    DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo).…

  • CVE-2026-82878MedAug 31, 2026
    risk 0.34cvss 6.3epss 0.00

    DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry,…

  • CVE-2026-8724MedMay 17, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been…

  • CVE-2026-32139MedMar 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether the XML is parseable and whether the root node is svg. It does not sanitize…

  • CVE-2026-90529LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument…

  • CVE-2023-40772MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.01

    A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

  • CVE-2025-57773CriAug 25, 2025
    risk 0.01cvss 9.8epss 0.08

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files.…

  • CVE-2025-57772CriAug 25, 2025
    risk 0.01cvss 9.8epss 0.09

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, the getJdbcUrl method is returned, which acts as the getter for the JdbcUrl parameter provided. This…