metabase
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting metabase.
- CVE-2026-50147Metabase: Arbitrary File Read via MySQL Connection Property Injection7.6
- CVE-2026-50148Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write10.0
- CVE-2026-59826Metabase: Arbitrary Code Execution via Database Connection Detail Bypass9.1
- CVE-2026-59827Metabase: Unsafe Deserialization of H2 Query Results9.9
- CVE-2026-33725Metabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import7.2
- CVE-2026-27464Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE7.7
- CVE-2025-5895Metabase dom.js parseDataUri redos4.3
- CVE-2025-27141Metabase Enterprise Edition allows cached questions to leak data to impersonated users6.5
- CVE-2023-37470Metabase vulnerable to remote code execution via POST /api/setup/validate API endpoint 10.0
- CVE-2023-38646Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not requ...9.8
- CVE-2023-32680Missing SQL permissions check in metabase5.8
- CVE-2023-23629Metabase subject to Improper Privilege Management6.3
- CVE-2023-23628Metabase subject to Exposure of Sensitive Information to an Unauthorized Actor 5.7
- CVE-2022-43776The url parameter of the /api/geojson endpoint in Metabase versions <44.5 can be used to perform Server Side Request Forgery attacks. Previously implemented blacklists could be circumvented by leve...6.5
- CVE-2022-39361Metabase vulnerable to Remote Code Execution via H28.8