OpenRefine records
15 published records for vendor openrefine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 86.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-36 Absolute Path Traversal1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2023-41887No exploit | Remote Code exec in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | Critical9.8 | — | 42.5% | Sep 15, 2023 |
36Monitor | CVE-2024-47883No exploit | Butterfly has path/URL confusion in resource handling leading to multiple weaknessesopenrefine · butterfly · CWE-36 | Critical9.1 | — | 1.6% | Oct 24, 2024 |
35Monitor | CVE-2024-47881No exploit | OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)openrefine · openrefine · CWE-89 | High8.8 | — | 0.7% | Oct 24, 2024 |
35Monitor | CVE-2024-47879No exploit | OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)openrefine · openrefine · CWE-94 | High8.8 | — | 0.4% | Oct 24, 2024 |
31Monitor | CVE-2019-3580No exploit | OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.openrefine · openrefine · CWE-22 | High7.5 | — | 1.9% | Jan 2, 2019 |
31Monitor | CVE-2018-20157No exploit | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing atopenrefine · openrefine · CWE-611 | High7.5 | — | 1.7% | Dec 14, 2018 |
31Monitor | CVE-2023-37476No exploit | Zip slip in OpenRefineopenrefine · openrefine · CWE-22 | High7.8 | — | 0.6% | Jul 17, 2023 |
30Monitor | CVE-2024-23833No exploit | OpenRefine JDBC Attack Vulnerabilityopenrefine · openrefine · CWE-22 | High7.5 | — | 1.0% | Feb 12, 2024 |
30Monitor | CVE-2023-41886No exploit | OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attackopenrefine · openrefine · CWE-89 | High7.5 | — | 1.0% | Sep 15, 2023 |
27Monitor | CVE-2018-19859Proof of concept | OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.openrefine · openrefine · CWE-22 | Medium6.5 | — | 2.4% | Dec 5, 2018 |
27Monitor | CVE-2024-47880No exploit | OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommandopenrefine · openrefine · CWE-79 | Medium6.9 | — | 0.4% | Oct 24, 2024 |
26Monitor | CVE-2022-41401Proof of concept | OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, poopenrefine · openrefine · CWE-918 | Medium6.5 | — | 1.4% | Aug 4, 2023 |
24Monitor | CVE-2024-47882No exploit | OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious projectopenrefine · openrefine · CWE-79 | Medium6.1 | — | 0.5% | Oct 24, 2024 |
24Monitor | CVE-2024-47878No exploit | Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)openrefine · openrefine · CWE-79 | Medium6.1 | — | 0.4% | Oct 24, 2024 |
21Monitor | CVE-2024-49760No exploit | OpenRefine has a path traversal in LoadLanguageCommandopenrefine · openrefine · CWE-22 | Medium5.3 | — | 0.6% | Oct 24, 2024 |
- CVE-2023-4188752Plan
Remote Code exec in project import with mysql jdbc url attack
CriticalCVSS 9.8No exploitEPSS 43%openrefine · openrefineSep 15, 2023
- CVE-2024-4788336Monitor
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
CriticalCVSS 9.1No exploitEPSS 2%openrefine · butterflyOct 24, 2024
- CVE-2024-4788135Monitor
OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
HighCVSS 8.8No exploitEPSS 1%openrefine · openrefineOct 24, 2024
- CVE-2024-4787935Monitor
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%openrefine · openrefineOct 24, 2024
- CVE-2019-358031Monitor
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
HighCVSS 7.5No exploitEPSS 2%openrefine · openrefineJan 2, 2019
- CVE-2018-2015731Monitor
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing at
HighCVSS 7.5No exploitEPSS 2%openrefine · openrefineDec 14, 2018
- CVE-2023-3747631Monitor
Zip slip in OpenRefine
HighCVSS 7.8No exploitEPSS 1%openrefine · openrefineJul 17, 2023
- CVE-2024-2383330Monitor
OpenRefine JDBC Attack Vulnerability
HighCVSS 7.5No exploitEPSS 1%openrefine · openrefineFeb 12, 2024
- CVE-2023-4188630Monitor
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
HighCVSS 7.5No exploitEPSS 1%openrefine · openrefineSep 15, 2023
- CVE-2018-1985927Monitor
OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.
MediumCVSS 6.5Proof of conceptEPSS 2%openrefine · openrefineDec 5, 2018
- CVE-2024-4788027Monitor
OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
MediumCVSS 6.9No exploitEPSS 0%openrefine · openrefineOct 24, 2024
- CVE-2022-4140126Monitor
OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to exploit the system, po
MediumCVSS 6.5Proof of conceptEPSS 1%openrefine · openrefineAug 4, 2023
- CVE-2024-4788224Monitor
OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
MediumCVSS 6.1No exploitEPSS 0%openrefine · openrefineOct 24, 2024
- CVE-2024-4787824Monitor
Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
MediumCVSS 6.1No exploitEPSS 0%openrefine · openrefineOct 24, 2024
- CVE-2024-4976021Monitor
OpenRefine has a path traversal in LoadLanguageCommand
MediumCVSS 5.3No exploitEPSS 1%openrefine · openrefineOct 24, 2024