Knowage
This hub aggregates every CVE we track for Knowage. Use it to gauge the current risk picture and drill into individual advisories.
other
26
CVEs tracked
4
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM16HIGH5CRITICAL4LOW1
Monthly trend
0
0
0
0
0
1
0
0
0
0
0
0
2
0
0
0
1
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Knowage.
- CVE-2025-58441Knowage is vulnerable to blind server-side request forgery (SSRF)6.5
- CVE-2025-59954Knowage Contains a Remote Code Execution Vulnerability9.8
- CVE-2025-55007Knowage vulnerable to server-side request forgery3.5
- CVE-2024-57971DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.9.1
- CVE-2023-38702Knowage Server vulnerable to path traversal via upload functionality9.9
- CVE-2023-37472Query injection in Knowage server7.7
- CVE-2023-36819Knowage-Server vulnerable to Path traversal in download functionalities6.5
- CVE-2023-35154Knowage-Server vulnerable to account validation bypass7.2
- CVE-2022-39295Improper Neutralization of Alternate XSS Syntax in Knowage-Server6.1
- CVE-2021-30213Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.6.1
- CVE-2021-30214Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.5.4
- CVE-2021-30212Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.5.4
- CVE-2021-30211Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.5.4
- CVE-2021-30055A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.8.8
- CVE-2021-30056Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead ...5.4
Product normalization is registry-driven with AI assist and human review. How it works