dataease
Latest CVEs
The 15 most recently published vulnerabilities affecting dataease.
- CVE-2026-8724Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection4.7
- CVE-2026-42463SQLBot: Unauthorized Access Vulnerability8.1
- CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code execution8.8
- CVE-2026-40901DataEase: Quartz Deserialization → Remote Code Execution8.8
- CVE-2026-40900DataEase has SQL Injection via Stacked Queries8.8
- CVE-2026-40899DataEase has an Arbitrary File Read Vulnerability6.5
- CVE-2026-33207DataEase SQL Injection Vulnerability8.8
- CVE-2026-33122DataEase has SQL Injection via Datasource Management9.8
- CVE-2026-33121DataEase has SQL Injection via Datasource Save Flow8.8
- CVE-2026-33084DataEase has SQL Injection through its getFieldEnumObj Endpoint8.8
- CVE-2026-33083DataEase has SQL Injection in Order By Clause8.8
- CVE-2026-33082DataEase: SQL Injection in v2 Dataset Export9.8
- CVE-2026-5417Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery4.7
- CVE-2026-32950SQLBot: RCE via SQL Injection in Excel Upload Endpoint8.8
- CVE-2026-32949SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL7.5