tableau records
22 published records for vendor tableau.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 59.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-6939No exploit | Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users.tableau · tableau server | Critical9.8 | — | 1.8% | Nov 23, 2020 |
39Monitor | CVE-2022-22128No exploit | Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could tableau · tableau server · CWE-22 | Critical9.8 | — | 1.5% | Oct 17, 2022 |
37Monitor | CVE-2025-26496No exploit | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux tableau · tableau server · CWE-843 | Critical9.3 | — | 0.2% | Aug 22, 2025 |
36Monitor | CVE-2019-15637Proof of concept | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a tableau · tableau server · CWE-611 | High8.1 | — | 14.3% | Aug 26, 2019 |
34Monitor | CVE-2025-52452No exploit | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux tableau · tableau server · CWE-22 | High8.5 | — | 0.4% | Jul 25, 2025 |
34Monitor | CVE-2025-52449No exploit | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service motableau · tableau server · CWE-434 | High8.5 | — | 0.3% | Jul 25, 2025 |
34Monitor | CVE-2025-52451No exploit | Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modtableau · tableau server · CWE-20 | High8.5 | — | 0.2% | Aug 22, 2025 |
32Monitor | CVE-2025-52447No exploit | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc commantableau · tableau server · CWE-639 | High8.1 | — | 0.4% | Jul 25, 2025 |
32Monitor | CVE-2025-52448No exploit | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modutableau · tableau server · CWE-639 | High8.1 | — | 0.4% | Jul 25, 2025 |
32Monitor | CVE-2025-52453No exploit | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Ltableau · tableau server · CWE-918 | High8.2 | — | 0.3% | Jul 25, 2025 |
32Monitor | CVE-2025-52454No exploit | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resourctableau · tableau server · CWE-918 | High8.2 | — | 0.3% | Jul 25, 2025 |
32Monitor | CVE-2025-52446No exploit | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Itableau · tableau server · CWE-639 | High8.0 | — | 0.2% | Jul 25, 2025 |
31Monitor | CVE-2019-19719No exploit | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.tableau · tableau server · CWE-79 | Medium6.1 | — | 22.0% | Dec 11, 2019 |
30Monitor | CVE-2020-6938No exploit | A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow atableau · tableau server · CWE-532 | High7.5 | — | 1.2% | Jul 8, 2020 |
30Monitor | CVE-2025-26494No exploit | Server Side Request Forgery vulnerability in Tableau Servertableau · tableau server · CWE-918 | High7.7 | — | 0.6% | Feb 11, 2025 |
30Monitor | CVE-2025-26495No exploit | Sensitive Data Exposure in Tableau Servertableau · tableau server · CWE-312 | High7.5 | — | 0.3% | Feb 11, 2025 |
29Monitor | CVE-2025-26498No exploit | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo mtableau · tableau server · CWE-434 | High7.3 | — | 0.3% | Aug 22, 2025 |
29Monitor | CVE-2025-26497No exploit | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Abtableau · tableau server · CWE-434 | High7.3 | — | 0.3% | Aug 22, 2025 |
28Monitor | CVE-2022-22127No exploit | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity tableau · tableau server | High7.2 | — | 1.1% | May 25, 2022 |
26Monitor | CVE-2025-52450No exploit | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux tableau · tableau server · CWE-22 | Medium6.5 | — | 0.4% | Aug 22, 2025 |
24Monitor | CVE-2021-1629No exploit | Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.tableau · tableau server · CWE-601 | Medium6.1 | — | 1.3% | Mar 26, 2021 |
21Monitor | CVE-2025-52455No exploit | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Locatiotableau · tableau server · CWE-918 | Medium5.3 | — | 0.3% | Jul 25, 2025 |
- CVE-2020-693940Plan
Tableau Server installations configured with Site-Specific SAML that allows the APIs to be used by unauthenticated users.
CriticalCVSS 9.8No exploitEPSS 2%tableau · tableau serverNov 23, 2020
- CVE-2022-2212839Monitor
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could
CriticalCVSS 9.8No exploitEPSS 2%tableau · tableau serverOct 17, 2022
- CVE-2025-2649637Monitor
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux
CriticalCVSS 9.3No exploitEPSS 0%tableau · tableau serverAug 22, 2025
- CVE-2019-1563736Monitor
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a
HighCVSS 8.1Proof of conceptEPSS 14%tableau · tableau serverAug 26, 2019
- CVE-2025-5245234Monitor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux
HighCVSS 8.5No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5244934Monitor
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service mo
HighCVSS 8.5No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5245134Monitor
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload mod
HighCVSS 8.5No exploitEPSS 0%tableau · tableau serverAug 22, 2025
- CVE-2025-5244732Monitor
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc comman
HighCVSS 8.1No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5244832Monitor
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modu
HighCVSS 8.1No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5245332Monitor
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource L
HighCVSS 8.2No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5245432Monitor
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resourc
HighCVSS 8.2No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2025-5244632Monitor
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows I
HighCVSS 8.0No exploitEPSS 0%tableau · tableau serverJul 25, 2025
- CVE-2019-1971931Monitor
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
MediumCVSS 6.1No exploitEPSS 22%tableau · tableau serverDec 11, 2019
- CVE-2020-693830Monitor
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow a
HighCVSS 7.5No exploitEPSS 1%tableau · tableau serverJul 8, 2020
- CVE-2025-2649430Monitor
Server Side Request Forgery vulnerability in Tableau Server
HighCVSS 7.7No exploitEPSS 1%tableau · tableau serverFeb 11, 2025
- CVE-2025-2649530Monitor
Sensitive Data Exposure in Tableau Server
HighCVSS 7.5No exploitEPSS 0%tableau · tableau serverFeb 11, 2025
- CVE-2025-2649829Monitor
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo m
HighCVSS 7.3No exploitEPSS 0%tableau · tableau serverAug 22, 2025
- CVE-2025-2649729Monitor
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Ab
HighCVSS 7.3No exploitEPSS 0%tableau · tableau serverAug 22, 2025
- CVE-2022-2212728Monitor
Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers using Local Identity
HighCVSS 7.2No exploitEPSS 1%tableau · tableau serverMay 25, 2022
- CVE-2025-5245026Monitor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux
MediumCVSS 6.5No exploitEPSS 0%tableau · tableau serverAug 22, 2025
- CVE-2021-162924Monitor
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
MediumCVSS 6.1No exploitEPSS 1%tableau · tableau serverMar 26, 2021
- CVE-2025-5245521Monitor
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Locatio
MediumCVSS 5.3No exploitEPSS 0%tableau · tableau serverJul 25, 2025