Spagobi
This hub aggregates every CVE we track for Spagobi, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Enterprise Softwareother
8
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH2LOW1CRITICAL1
Monthly trend
0
0
0
0
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Spagobi.
- CVE-2024-54795SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.5.4
- CVE-2024-54794The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.9.1
- CVE-2024-54792A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions insi...6.1
- CVE-2013-6231SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script8.8
- CVE-2013-6234Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, ...8.0
- CVE-2014-7296The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted X...6.8
- CVE-2013-6233Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."4.3
- CVE-2013-6232Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.3.5
Product normalization is registry-driven with AI assist and human review. How it works