VYPR

Dataease

by Dataease

Source repositories

CVEs (97)

  • CVE-2026-50124HigJul 15, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where…

  • CVE-2026-50030HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts PreviewSqlDTO.sql, PreviewSqlDTO.datasourceId, and PreviewSqlDTO.isCross,…

  • CVE-2026-49867MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.staticResource through POST /de2api/templateManage/save or DataVisualizationServer.decompression, after…

  • CVE-2026-46684CriJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and length before userBOByToken(token) uses…

  • CVE-2026-45535HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and SqlparserUtils.handleVariableDefaultValue() inserts them with String.replace() without…

  • CVE-2026-45534CriJul 15, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.F…

  • CVE-2026-45533HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCenterManage.delete, allowing…

  • CVE-2026-45419HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticResource names and…

  • CVE-2026-45417HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with executeQuery in io.dataease.datasource.provider.CalciteProvid…

  • CVE-2026-45320HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user input for non-in and non-between operators before…

  • CVE-2026-57172HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to…

  • CVE-2026-55647MedJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an authenticated user who can edit dashboard component data to inject HTML…

  • CVE-2026-55635HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without applying the SQL literal validation and escaping used by…

  • CVE-2026-55633HigJul 7, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontManage.saveFile and then exploit it…

  • CVE-2026-55631HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record is later deleted, the backend concatenates that stored value…

  • CVE-2026-53751HigJul 7, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between DataEase validation and H2 parsing, allowing attackers to…

  • CVE-2026-53730HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated user to specify datasourceId=-1, access the built-in engine…

  • CVE-2026-53729HigJul 7, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate download links…

  • CVE-2026-50530HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared…

  • CVE-2026-50529HigJul 7, 2026
    risk 0.00cvss —epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket, allowing unauthenticated attackers who know a protected share UUID…

Page 4 of 5