open-metadata records
12 published records for vendor open-metadata.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 16.7%
- Pre-auth RCE
- 0
- With a fix record
- 58.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-269 Improper Privilege Management1
- CWE-287 Improper Authentication1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2024-28255Weaponized | Authentication Bypass in OpenMetadataopen-metadata · openmetadata · CWE-287 | Critical9.8 | — | 73.3% | Mar 15, 2024 |
49Plan | CVE-2024-28254Weaponized | SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadataopen-metadata · openmetadata · CWE-78 | High8.8 | — | 45.7% | Mar 15, 2024 |
39Monitor | CVE-2024-28253Proof of concept | SpEL Injection in `PUT /api/v1/policies` in OpenMetadataopen-metadata · openmetadata · CWE-94 | High8.8 | — | 12.5% | Mar 15, 2024 |
37Monitor | CVE-2024-28848No exploit | SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` in OpenMetadataopen-metadata · openmetadata · CWE-94 | High8.8 | — | 7.9% | Mar 15, 2024 |
36Monitor | CVE-2024-28847No exploit | SpEL Injection in `PUT /api/v1/events/subscriptions` in OpenMetadataopen-metadata · openmetadata · CWE-94 | High8.8 | — | 2.4% | Mar 15, 2024 |
35Monitor | CVE-2024-55238No exploit | OpenMetadata <=1.4.1 is vulnerable to SQL Injection.open-metadata · openmetadata · CWE-89 | High8.8 | — | 0.6% | Apr 17, 2025 |
35Monitor | CVE-2025-50465No exploit | OpenMetadata <=1.4.4 is vulnerable to SQL Injection.open-metadata · openmetadata · CWE-89 | High8.8 | — | 0.3% | Aug 8, 2025 |
34Monitor | CVE-2026-22244No exploit | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopen-metadata · openmetadata · CWE-1336 | High8.5 | — | 1.3% | Jan 8, 2026 |
30Monitor | CVE-2026-26010No exploit | Leaky JWTs in OpenMetadata exposing highly-privileged bot usersopen-metadata · openmetadata · CWE-269 | High7.6 | — | 0.4% | Feb 11, 2026 |
26Monitor | CVE-2025-50466No exploit | OpenMetadata <=1.4.4 is vulnerable to SQL Injection.open-metadata · openmetadata · CWE-89 | Medium6.5 | — | 0.3% | Aug 8, 2025 |
26Monitor | CVE-2025-50468No exploit | OpenMetadata <=1.4.4 is vulnerable to SQL Injection.open-metadata · openmetadata · CWE-89 | Medium6.5 | — | 0.3% | Aug 8, 2025 |
26Monitor | CVE-2025-50467No exploit | OpenMetadata <=1.4.4 is vulnerable to SQL Injection.open-metadata · openmetadata · CWE-89 | Medium6.5 | — | 0.3% | Aug 8, 2025 |
- CVE-2024-2825561This week
Authentication Bypass in OpenMetadata
CriticalCVSS 9.8WeaponizedEPSS 73%open-metadata · openmetadataMar 15, 2024
- CVE-2024-2825449Plan
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
HighCVSS 8.8WeaponizedEPSS 46%open-metadata · openmetadataMar 15, 2024
- CVE-2024-2825339Monitor
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
HighCVSS 8.8Proof of conceptEPSS 13%open-metadata · openmetadataMar 15, 2024
- CVE-2024-2884837Monitor
SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` in OpenMetadata
HighCVSS 8.8No exploitEPSS 8%open-metadata · openmetadataMar 15, 2024
- CVE-2024-2884736Monitor
SpEL Injection in `PUT /api/v1/events/subscriptions` in OpenMetadata
HighCVSS 8.8No exploitEPSS 2%open-metadata · openmetadataMar 15, 2024
- CVE-2024-5523835Monitor
OpenMetadata <=1.4.1 is vulnerable to SQL Injection.
HighCVSS 8.8No exploitEPSS 1%open-metadata · openmetadataApr 17, 2025
- CVE-2025-5046535Monitor
OpenMetadata <=1.4.4 is vulnerable to SQL Injection.
HighCVSS 8.8No exploitEPSS 0%open-metadata · openmetadataAug 8, 2025
- CVE-2026-2224434Monitor
OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE
HighCVSS 8.5No exploitEPSS 1%open-metadata · openmetadataJan 8, 2026
- CVE-2026-2601030Monitor
Leaky JWTs in OpenMetadata exposing highly-privileged bot users
HighCVSS 7.6No exploitEPSS 0%open-metadata · openmetadataFeb 11, 2026
- CVE-2025-5046626Monitor
OpenMetadata <=1.4.4 is vulnerable to SQL Injection.
MediumCVSS 6.5No exploitEPSS 0%open-metadata · openmetadataAug 8, 2025
- CVE-2025-5046826Monitor
OpenMetadata <=1.4.4 is vulnerable to SQL Injection.
MediumCVSS 6.5No exploitEPSS 0%open-metadata · openmetadataAug 8, 2025
- CVE-2025-5046726Monitor
OpenMetadata <=1.4.4 is vulnerable to SQL Injection.
MediumCVSS 6.5No exploitEPSS 0%open-metadata · openmetadataAug 8, 2025