VYPR
Vendor

Metabase

Products
1
CVEs
31
Across products
31
Status
Private

Products

1

Recent CVEs

31
View all 31 CVEs →
  • CVE-2026-72898CriKEVAug 10, 2026
    risk 0.77cvss 10.0epss 0.10

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

  • CVE-2023-38646CriJul 21, 2023
    risk 0.68cvss 9.8epss 0.99

    Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1,…

  • CVE-2026-72899CriAug 10, 2026
    risk 0.65cvss 10.0epss 0.01

    Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

  • CVE-2023-37470CriAug 4, 2023
    risk 0.65cvss 10.0epss 0.01

    Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue…

  • CVE-2022-39361HigOct 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 databases. This issue is…

  • CVE-2022-24855HigApr 14, 2022
    risk 0.57cvss 8.7epss 0.01

    Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links…

  • CVE-2026-22805HigJan 12, 2026
    risk 0.56cvss 8.6epss 0.00

    Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in…

  • CVE-2022-24854HigApr 14, 2022
    risk 0.52cvss 8.0epss 0.01

    Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databases via the initial connection. If the attacker has SQL permissions to at least one SQLite database,…

  • CVE-2026-27464HigFeb 21, 2026
    risk 0.50cvss 7.7epss 0.00

    Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed…

  • CVE-2026-33725HigMar 27, 2026
    risk 0.47cvss 7.2epss 0.01

    Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and…

  • CVE-2026-72900MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

  • CVE-2025-27141MedFeb 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with impersonation permissions may be…

  • CVE-2022-39358MedOct 26, 2022
    risk 0.42cvss 6.5epss 0.00

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This…

  • CVE-2022-43776MedOct 26, 2022
    risk 0.42cvss 6.5epss 0.01

    The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

  • CVE-2023-23629MedJan 28, 2023
    risk 0.41cvss 6.3epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone with greater access to data…

  • CVE-2018-0697MedNov 15, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2022-24853MedApr 14, 2022
    risk 0.39cvss 5.9epss 0.02

    Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted…

  • CVE-2023-23628MedJan 28, 2023
    risk 0.37cvss 5.7epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase application. However, when a…

  • CVE-2024-55951MedDec 16, 2024
    risk 0.24cvss epss 0.00

    Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52.1 or 1.5.2 should upgrade to…

  • CVE-2025-5895MedJun 9, 2025
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack…