VYPR

Vendor CVEs

Dataease

All CVEs

101 total · sorted by risk
  • CVE-2025-49002CriJun 3, 2025
    risk 0.67cvss 9.8epss 0.45

    DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability…

  • CVE-2025-49001CriJun 3, 2025
    risk 0.65cvss 9.8epss 0.22

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds…

  • CVE-2024-56511CriJan 10, 2025
    risk 0.65cvss 9.8epss 0.44

    DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter…

  • CVE-2025-53006CriJul 2, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg" with similar functionality.…

  • CVE-2025-53005CriJul 1, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass…

  • CVE-2025-53004CriJun 30, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass…

  • CVE-2025-49003CriJun 26, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" becomes "S" when converted…

  • CVE-2025-46566CriMay 1, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.

  • CVE-2025-32966CriApr 23, 2025
    risk 0.64cvss 9.8epss 0.04

    DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

  • CVE-2025-27138CriMar 13, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in…

  • CVE-2024-57707CriFeb 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

  • CVE-2024-46997CriSep 23, 2024
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.

  • CVE-2023-33963CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known…

  • CVE-2023-28437CriMar 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

  • CVE-2022-34113CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

  • CVE-2024-47073CriNov 7, 2024
    risk 0.59cvss 9.1epss 0.01

    DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any…

  • CVE-2026-33122CriApr 16, 2026
    risk 0.57cvss 9.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/datasource/update, the…

  • CVE-2026-33082CriApr 16, 2026
    risk 0.57cvss 9.8epss 0.00

    DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and…

  • CVE-2026-23958CriJan 22, 2026
    risk 0.57cvss 9.8epss 0.00

    Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting…

  • CVE-2025-48998HigJun 3, 2025
    risk 0.57cvss 8.8epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been…

  • CVE-2023-37258HigJul 25, 2023
    risk 0.57cvss 8.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

  • CVE-2022-39312CriOct 25, 2022
    risk 0.57cvss 9.8epss 0.02

    Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In…

  • CVE-2022-34115CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

  • CVE-2022-34114HigJul 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

  • CVE-2022-23331HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.01

    In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

  • CVE-2026-42463HigMay 13, 2026
    risk 0.53cvss 8.1epss 0.00

    SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and…

  • CVE-2023-34463HigJun 26, 2023
    risk 0.53cvss 8.1epss 0.01

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.…

  • CVE-2023-28637HigMar 28, 2023
    risk 0.52cvss 8.0epss 0.01

    DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code…

  • CVE-2026-40901HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.01

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3.2, also bundled in the…

  • CVE-2026-40900HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single…

  • CVE-2026-33207HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly…

  • CVE-2026-33121HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL…

  • CVE-2026-33084HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied…

  • CVE-2026-33083HigApr 16, 2026
    risk 0.50cvss 8.8epss 0.00

    DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and…

  • CVE-2026-32950HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user…

  • CVE-2026-32622HigMar 19, 2026
    risk 0.50cvss 8.8epss 0.01

    SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload…

  • CVE-2026-32140HigMar 12, 2026
    risk 0.50cvss 8.8epss 0.01

    Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to…

  • CVE-2026-32137HigMar 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string,…

  • CVE-2024-46985HigSep 23, 2024
    risk 0.49cvss 7.5epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource upload interface of DataEase. An attacker can construct a payload to implement intranet detection and file…

  • CVE-2024-31441HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in…

  • CVE-2023-40771HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

  • CVE-2021-38239HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.

  • CVE-2026-32939HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without specifying an explicit Locale,…

  • CVE-2023-32310HigJun 1, 2023
    risk 0.46cvss 8.1epss 0.01

    DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or…

  • CVE-2026-32949HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.00

    SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can…

  • CVE-2025-27103MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been…

  • CVE-2025-24974MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are…

  • CVE-2023-35168MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.01

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5…

  • CVE-2023-28435MedMar 24, 2023
    risk 0.42cvss 6.5epss 0.00

    Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These…

  • CVE-2023-35164MedJun 26, 2023
    risk 0.41cvss 6.3epss 0.00

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been…

Page 1 of 3