Superset
This hub aggregates every CVE we track for Superset, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
68
CVEs tracked
4
Critical
7
High
1
In CISA KEV
Severity distribution
MEDIUM55HIGH7CRITICAL4LOW2
Monthly trend
0
0
0
0
4
0
0
0
0
2
0
0
4
0
0
0
0
0
5
0
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Superset.
- CVE-2026-23969Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering6.5
- CVE-2026-23980Apache Superset: Improper Neutralization of Special Elements used in a SQL Command6.5
- CVE-2026-23982Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass6.5
- CVE-2026-23983Apache Superset: Sensitive Data Exposure via REST API (disabled by default)6.5
- CVE-2026-23984Apache Superset: SQLLab Read-Only Bypass on PostgreSQL6.5
- CVE-2025-55675Apache Superset: Incorrect datasource authorization on REST API6.5
- CVE-2025-55674Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions6.5
- CVE-2025-55672Apache Superset: Stored XSS on charts metadata5.4
- CVE-2025-55673Apache Superset: Metadata exposure in embedded charts4.3
- CVE-2025-48912Apache Superset: Improper authorization bypass on row level security via SQL Injection6.5
- CVE-2025-27696Apache Superset: Incorrect authorization leading to resource ownership takeover8.8
- CVE-2024-55633Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access6.5
- CVE-2024-53949Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled6.5
- CVE-2024-53948Apache Superset: Error verbosity exposes metadata in analytics databases5.3
- CVE-2024-53947Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions9.8
Product normalization is registry-driven with AI assist and human review. How it works