VYPR
Vendor

Dbgate

Products
1
CVEs
10
Across products
10
Status
Private

Products

1

Recent CVEs

10
  • CVE-2026-47668CriJul 23, 2026
    risk 0.58cvss 10.0epss 0.04

    DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated…

  • CVE-2026-47670CriJul 23, 2026
    risk 0.54cvss epss 0.02

    DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the…

  • CVE-2026-47669CriJul 23, 2026
    risk 0.53cvss epss 0.01

    DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes…

  • CVE-2026-85176HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.00

    DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including…

  • CVE-2026-48017HigJun 15, 2026
    risk 0.50cvss 8.8epss 0.01

    DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user…

  • CVE-2026-34725HigApr 2, 2026
    risk 0.46cvss 8.2epss 0.00

    DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another…

  • CVE-2025-50185HigJul 26, 2025
    risk 0.46cvss epss 0.00

    DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve data from arbitrary files on the system, regardless of their…

  • CVE-2026-6215MedApr 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side request forgery. The attack may be initiated remotely. The…

  • CVE-2025-50184HigJul 26, 2025
    risk 0.39cvss epss 0.01

    DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that lists files within the…

  • CVE-2026-6216LowApr 13, 2026
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The…