metabase records
26 published records for vendor metabase.
Researcher profile
- Entered KEV
- 2 · 7.7%
- Weaponized
- 3 · 11.5%
- Pre-auth RCE
- 2
- With a fix record
- 3.8%
- Median publish → KEV
- 546 days
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-502 Deserialization of Untrusted Data2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2021-41277Weaponized | GeoJSON URL validation can expose server files and environment variables to unauthorized usersmetabase · metabase · CWE-200 | High7.5 | KEV | 97.2% | Nov 17, 2021 |
76This week | CVE-2026-72898Weaponized | Metabase SQL injection via password reset endpointmetabase · metabase · CWE-89 | Critical10.0 | KEV | 19.0% | Aug 10, 2026 |
69This week | CVE-2023-38646Weaponized | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, atmetabase · metabase | Critical9.8 | — | 98.7% | Jul 21, 2023 |
39Monitor | CVE-2023-37470No exploit | Metabase vulnerable to remote code execution via POST /api/setup/validate API endpointmetabase · metabase · CWE-94 | Critical9.8 | — | 1.3% | Aug 4, 2023 |
38Monitor | CVE-2023-32680No exploit | Missing SQL permissions check in metabasemetabase · metabase · CWE-306 | Critical9.6 | — | 0.6% | May 18, 2023 |
36Monitor | CVE-2026-59827Proof of concept | Metabase: Unsafe Deserialization of H2 Query Resultsmetabase · metabase · CWE-502 | High8.8 | — | 3.8% | Jul 9, 2026 |
36Monitor | CVE-2026-59826No exploit | Metabase: Arbitrary Code Execution via Database Connection Detail Bypassmetabase · metabase · CWE-94 | Critical9.1 | — | 1.0% | Jul 9, 2026 |
36Monitor | CVE-2026-50148No exploit | Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Writemetabase · metabase · CWE-73 | Critical9.1 | — | 0.8% | Jul 15, 2026 |
35Monitor | CVE-2022-39361No exploit | Metabase vulnerable to Remote Code Execution via H2metabase · metabase · CWE-20 | High8.8 | — | 1.1% | Oct 26, 2022 |
35Monitor | CVE-2022-24854No exploit | Database bypassing any permissions in Metabase via SQlite attachmetabase · metabase · CWE-610 | High8.8 | — | 1.1% | Apr 14, 2022 |
35Monitor | CVE-2022-39362No exploit | Metabase vulnerable to arbitrary SQL execution from queryhashmetabase · metabase · CWE-356 | High8.8 | — | 0.9% | Oct 26, 2022 |
30Monitor | CVE-2026-50147No exploit | Metabase: Arbitrary File Read via MySQL Connection Property Injectionmetabase · metabase · CWE-88 | High7.6 | — | 0.3% | Jul 15, 2026 |
28Monitor | CVE-2026-33725Proof of concept | Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Importmetabase · metabase · CWE-502 | High7.2 | — | 0.8% | Mar 26, 2026 |
26Monitor | CVE-2022-43776No exploit | The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks.metabase · metabase · CWE-918 | Medium6.5 | — | 0.7% | Oct 26, 2022 |
26Monitor | CVE-2022-39359No exploit | Metabase's GeoJSON validation doesn't prevent redirects to blocked URLsmetabase · metabase · CWE-200 | Medium6.5 | — | 0.6% | Oct 26, 2022 |
26Monitor | CVE-2022-39360No exploit | Metabase SSO users able to circumvent IdP login by doing password resetmetabase · metabase · CWE-287 | Medium6.5 | — | 0.5% | Oct 26, 2022 |
26Monitor | CVE-2022-39358No exploit | Metabase vulnerable to circumvention of Locked parameter in Signed Embeddingmetabase · metabase · CWE-200 | Medium6.5 | — | 0.5% | Oct 26, 2022 |
26Monitor | CVE-2026-27464No exploit | Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCEmetabase · metabase · CWE-94 | Medium6.5 | — | 0.5% | Feb 21, 2026 |
25Monitor | CVE-2023-23629No exploit | Metabase subject to Improper Privilege Managementmetabase · metabase · CWE-200 | Medium6.3 | — | 0.4% | Jan 27, 2023 |
24Monitor | CVE-2018-0697No exploit | Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML viametabase · metabase · CWE-79 | Medium6.1 | — | 0.8% | Nov 15, 2018 |
22Monitor | CVE-2022-24853Proof of concept | File system exposure in Metabasemetabase · metabase · CWE-200 | Medium5.3 | — | 2.5% | Apr 14, 2022 |
21Monitor | CVE-2022-24855No exploit | XSS vulnerability in Metabasemetabase · metabase · CWE-79 | Medium5.4 | — | 0.7% | Apr 14, 2022 |
19Monitor | CVE-2025-27141No exploit | Metabase Enterprise Edition allows cached questions to leak data to impersonated usersmetabase · metabase · CWE-732 | Medium4.8 | — | 0.4% | Feb 24, 2025 |
16Monitor | CVE-2023-23628No exploit | Metabase subject to Exposure of Sensitive Information to an Unauthorized Actormetabase · metabase · CWE-200 | Medium4.1 | — | 0.4% | Jan 27, 2023 |
8Monitor | CVE-2025-5895No exploit | Metabase dom.js parseDataUri redosmetabase · metabase · CWE-400 | Low2.1 | — | 0.6% | Jun 9, 2025 |
- CVE-2021-4127789Now
GeoJSON URL validation can expose server files and environment variables to unauthorized users
HighCVSS 7.5KEVWeaponizedEPSS 97%metabase · metabaseNov 17, 2021
- CVE-2026-7289876This week
Metabase SQL injection via password reset endpoint
CriticalCVSS 10.0KEVWeaponizedEPSS 19%metabase · metabaseAug 10, 2026
- CVE-2023-3864669This week
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at
CriticalCVSS 9.8WeaponizedEPSS 99%metabase · metabaseJul 21, 2023
- CVE-2023-3747039Monitor
Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint
CriticalCVSS 9.8No exploitEPSS 1%metabase · metabaseAug 4, 2023
- CVE-2023-3268038Monitor
Missing SQL permissions check in metabase
CriticalCVSS 9.6No exploitEPSS 1%metabase · metabaseMay 18, 2023
- CVE-2026-5982736Monitor
Metabase: Unsafe Deserialization of H2 Query Results
HighCVSS 8.8Proof of conceptEPSS 4%metabase · metabaseJul 9, 2026
- CVE-2026-5982636Monitor
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
CriticalCVSS 9.1No exploitEPSS 1%metabase · metabaseJul 9, 2026
- CVE-2026-5014836Monitor
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
CriticalCVSS 9.1No exploitEPSS 1%metabase · metabaseJul 15, 2026
- CVE-2022-3936135Monitor
Metabase vulnerable to Remote Code Execution via H2
HighCVSS 8.8No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2022-2485435Monitor
Database bypassing any permissions in Metabase via SQlite attach
HighCVSS 8.8No exploitEPSS 1%metabase · metabaseApr 14, 2022
- CVE-2022-3936235Monitor
Metabase vulnerable to arbitrary SQL execution from queryhash
HighCVSS 8.8No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2026-5014730Monitor
Metabase: Arbitrary File Read via MySQL Connection Property Injection
HighCVSS 7.6No exploitEPSS 0%metabase · metabaseJul 15, 2026
- CVE-2026-3372528Monitor
Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import
HighCVSS 7.2Proof of conceptEPSS 1%metabase · metabaseMar 26, 2026
- CVE-2022-4377626Monitor
The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks.
MediumCVSS 6.5No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2022-3935926Monitor
Metabase's GeoJSON validation doesn't prevent redirects to blocked URLs
MediumCVSS 6.5No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2022-3936026Monitor
Metabase SSO users able to circumvent IdP login by doing password reset
MediumCVSS 6.5No exploitEPSS 1%metabase · metabaseOct 26, 2022
- CVE-2022-3935826Monitor
Metabase vulnerable to circumvention of Locked parameter in Signed Embedding
MediumCVSS 6.5No exploitEPSS 0%metabase · metabaseOct 26, 2022
- CVE-2026-2746426Monitor
Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE
MediumCVSS 6.5No exploitEPSS 0%metabase · metabaseFeb 21, 2026
- CVE-2023-2362925Monitor
Metabase subject to Improper Privilege Management
MediumCVSS 6.3No exploitEPSS 0%metabase · metabaseJan 27, 2023
- CVE-2018-069724Monitor
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 6.1No exploitEPSS 1%metabase · metabaseNov 15, 2018
- CVE-2022-2485322Monitor
File system exposure in Metabase
MediumCVSS 5.3Proof of conceptEPSS 3%metabase · metabaseApr 14, 2022
- CVE-2022-2485521Monitor
XSS vulnerability in Metabase
MediumCVSS 5.4No exploitEPSS 1%metabase · metabaseApr 14, 2022
- CVE-2025-2714119Monitor
Metabase Enterprise Edition allows cached questions to leak data to impersonated users
MediumCVSS 4.8No exploitEPSS 0%metabase · metabaseFeb 24, 2025
- CVE-2023-2362816Monitor
Metabase subject to Exposure of Sensitive Information to an Unauthorized Actor
MediumCVSS 4.1No exploitEPSS 0%metabase · metabaseJan 27, 2023
- CVE-2025-58958Monitor
Metabase dom.js parseDataUri redos
LowCVSS 2.1No exploitEPSS 1%metabase · metabaseJun 9, 2025