All 67 CVE vulnerabilities found in Apache Superset, with AI-generated Chinese analysis, references, and POCs.
This page aggregates recorded security vulnerabilities affecting Apache Superset, an open-source business intelligence platform maintained by the Apache Software Foundation. The collection focuses on known flaws including authentication bypasses, cross-site scripting, and remote code execution issues, covering advisories published from the project’s initial release through the current stable version. Here, you can track the vendor’s security advisory history, analyze the distribution of specific weakness classes like injection or improper input validation, and review the product’s complete vulnerability timeline without being distracted by marketing language or individual CVE listings.
Vendor: Apache Software Foundation
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-41971 | Possible SQL Injection when template processing is enabled CWE-89 | 8.8 | - | 2021-10-18 |
| CVE-2021-32609 | XSS vulnerability on Explore page CWE-79 | 6.4 | - | 2021-10-18 |
| CVE-2021-28125 | Apache Superset Open Redirect CWE-601 | 6.1 | - | 2021-04-27 |
| CVE-2021-27907 | Apache Superset stored XSS on Dashboard markdown CWE-79 | 5.4 | - | 2021-03-05 |
| CVE-2020-13952 | Apache Superset 安全漏洞 | 8.1 | - | 2020-09-30 |
| CVE-2020-13948 | apache superset 安全漏洞 | 8.8 | - | 2020-09-17 |
| CVE-2020-1932 | Apache Superset 信息泄露漏洞 | 6.5 | - | 2020-01-28 |
All 67 known CVE vulnerabilities affecting Apache Superset with full Chinese analysis, references, and POCs where available.