VYPR

Vendor CVEs

Metabase

All CVEs

31 total · sorted by risk
  • CVE-2026-72898CriKEVAug 10, 2026
    risk 0.77cvss 10.0epss 0.10

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

  • CVE-2023-38646CriJul 21, 2023
    risk 0.68cvss 9.8epss 0.99

    Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1,…

  • CVE-2026-72899CriAug 10, 2026
    risk 0.65cvss 10.0epss 0.01

    Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

  • CVE-2023-37470CriAug 4, 2023
    risk 0.65cvss 10.0epss 0.01

    Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue…

  • CVE-2022-39361HigOct 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, H2 (Sample Database) could allow Remote Code Execution (RCE), which can be abused by users able to write SQL queries on H2 databases. This issue is…

  • CVE-2022-24855HigApr 14, 2022
    risk 0.57cvss 8.7epss 0.01

    Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, potentially leading to phishing attempts with malicious links…

  • CVE-2026-22805HigJan 12, 2026
    risk 0.56cvss 8.6epss 0.00

    Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in…

  • CVE-2022-24854HigApr 14, 2022
    risk 0.52cvss 8.0epss 0.01

    Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTACH DATABASE`, which allows connecting multiple SQLite databases via the initial connection. If the attacker has SQL permissions to at least one SQLite database,…

  • CVE-2026-27464HigFeb 21, 2026
    risk 0.50cvss 7.7epss 0.00

    Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed…

  • CVE-2026-33725HigMar 27, 2026
    risk 0.47cvss 7.2epss 0.01

    Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and…

  • CVE-2026-72900MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

  • CVE-2025-27141MedFeb 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2 of Metabase Enterprise Edition, users with impersonation permissions may be…

  • CVE-2022-39358MedOct 26, 2022
    risk 0.42cvss 6.5epss 0.00

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was possible to circumvent locked parameters when requesting data for a question in an embedded dashboard by constructing a malicious request to the backend. This…

  • CVE-2022-43776MedOct 26, 2022
    risk 0.42cvss 6.5epss 0.01

    The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leveraging 301 and 302 redirects.

  • CVE-2023-23629MedJan 28, 2023
    risk 0.41cvss 6.3epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashboards subscriptions can view the data as seen by the creator of that subscription. This allows someone with greater access to data…

  • CVE-2018-0697MedNov 15, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2022-24853MedApr 14, 2022
    risk 0.39cvss 5.9epss 0.02

    Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs for JSON maps as part of our GeoJSON support. While we do validation to not return contents of arbitrary URLs, there is a case where a particularly crafted…

  • CVE-2023-23628MedJan 28, 2023
    risk 0.37cvss 5.7epss 0.00

    Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information to an Unauthorized Actor. Sandboxed users shouldn't be able to view data about other Metabase users anywhere in the Metabase application. However, when a…

  • CVE-2024-55951MedDec 16, 2024
    risk 0.24cvss epss 0.00

    Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52.1 or 1.5.2 should upgrade to…

  • CVE-2025-5895MedJun 9, 2025
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack…

  • CVE-2021-41277CriKEVNov 17, 2021
    risk 0.20cvss 10.0epss 0.97

    Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not…

  • CVE-2025-30371LowMar 28, 2025
    risk 0.07cvss epss 0.00

    Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature…

  • CVE-2025-32382LowApr 10, 2025
    risk 0.05cvss epss 0.00

    Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge older Snowflake connection…

  • CVE-2026-50148CriJul 15, 2026
    risk 0.00cvss 10.0epss 0.00

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the…

  • CVE-2026-50147HigJul 15, 2026
    risk 0.00cvss 7.6epss 0.00

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe…

  • CVE-2026-59827CriJul 9, 2026
    risk 0.00cvss 9.9epss 0.01

    Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native…

  • CVE-2026-59826CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.00

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to…

  • CVE-2023-32680MedMay 18, 2023
    risk 0.00cvss 5.8epss 0.01

    Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with native query editing permissions to a database–but affected versions of Metabase didn't enforce that requirement. This lack of…

  • CVE-2022-39362HigOct 26, 2022
    risk 0.00cvss 8.8epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries are auto-executed, which could pose a possible attack vector. This issue is patched in versions 0.44.5, 1.44.5, 0.43.7, 1.43.7,…

  • CVE-2022-39360MedOct 26, 2022
    risk 0.00cvss 6.5epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without going through the SSO IdP. This issue is…

  • CVE-2022-39359MedOct 26, 2022
    risk 0.00cvss 6.5epss 0.01

    Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, custom GeoJSON map URL address would follow redirects to addresses that were otherwise disallowed, like link-local or private-network. This issue is…