Skip to content
Noroxi

metabase records

26 published records for vendor metabase.

All records

26 records
  • GeoJSON URL validation can expose server files and environment variables to unauthorized users

    HighCVSS 7.5KEVWeaponizedEPSS 97%

    metabase · metabaseNov 17, 2021

  • CVE-2026-72898
    76This week

    Metabase SQL injection via password reset endpoint

    CriticalCVSS 10.0KEVWeaponizedEPSS 19%

    metabase · metabaseAug 10, 2026

  • CVE-2023-38646
    69This week

    Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at

    CriticalCVSS 9.8WeaponizedEPSS 99%

    metabase · metabaseJul 21, 2023

  • Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint

    CriticalCVSS 9.8No exploitEPSS 1%

    metabase · metabaseAug 4, 2023

  • Missing SQL permissions check in metabase

    CriticalCVSS 9.6No exploitEPSS 1%

    metabase · metabaseMay 18, 2023

  • Metabase: Unsafe Deserialization of H2 Query Results

    HighCVSS 8.8Proof of conceptEPSS 4%

    metabase · metabaseJul 9, 2026

  • Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

    CriticalCVSS 9.1No exploitEPSS 1%

    metabase · metabaseJul 9, 2026

  • Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write

    CriticalCVSS 9.1No exploitEPSS 1%

    metabase · metabaseJul 15, 2026

  • Metabase vulnerable to Remote Code Execution via H2

    HighCVSS 8.8No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • Database bypassing any permissions in Metabase via SQlite attach

    HighCVSS 8.8No exploitEPSS 1%

    metabase · metabaseApr 14, 2022

  • Metabase vulnerable to arbitrary SQL execution from queryhash

    HighCVSS 8.8No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • Metabase: Arbitrary File Read via MySQL Connection Property Injection

    HighCVSS 7.6No exploitEPSS 0%

    metabase · metabaseJul 15, 2026

  • Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import

    HighCVSS 7.2Proof of conceptEPSS 1%

    metabase · metabaseMar 26, 2026

  • The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks.

    MediumCVSS 6.5No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • Metabase's GeoJSON validation doesn't prevent redirects to blocked URLs

    MediumCVSS 6.5No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • Metabase SSO users able to circumvent IdP login by doing password reset

    MediumCVSS 6.5No exploitEPSS 1%

    metabase · metabaseOct 26, 2022

  • Metabase vulnerable to circumvention of Locked parameter in Signed Embedding

    MediumCVSS 6.5No exploitEPSS 0%

    metabase · metabaseOct 26, 2022

  • Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE

    MediumCVSS 6.5No exploitEPSS 0%

    metabase · metabaseFeb 21, 2026

  • Metabase subject to Improper Privilege Management

    MediumCVSS 6.3No exploitEPSS 0%

    metabase · metabaseJan 27, 2023

  • CVE-2018-0697
    24Monitor

    Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 6.1No exploitEPSS 1%

    metabase · metabaseNov 15, 2018

  • File system exposure in Metabase

    MediumCVSS 5.3Proof of conceptEPSS 3%

    metabase · metabaseApr 14, 2022

  • XSS vulnerability in Metabase

    MediumCVSS 5.4No exploitEPSS 1%

    metabase · metabaseApr 14, 2022

  • Metabase Enterprise Edition allows cached questions to leak data to impersonated users

    MediumCVSS 4.8No exploitEPSS 0%

    metabase · metabaseFeb 24, 2025

  • Metabase subject to Exposure of Sensitive Information to an Unauthorized Actor

    MediumCVSS 4.1No exploitEPSS 0%

    metabase · metabaseJan 27, 2023

  • Metabase dom.js parseDataUri redos

    LowCVSS 2.1No exploitEPSS 1%

    metabase · metabaseJun 9, 2025