Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dataease — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting dataease. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DataEase is an open-source data visualization and analytics tool designed to simplify business intelligence by enabling users to create dashboards from diverse data sources. Despite its utility, the platform has accumulated 71 recorded Common Vulnerabilities and Exposures, indicating significant historical security hygiene issues. Analysis of these vulnerabilities reveals a prevalence of remote code execution, cross-site scripting, and authentication bypass flaws, often stemming from insufficient input validation and improper access control mechanisms. These defects frequently allow unauthenticated attackers to compromise system integrity or escalate privileges within the application environment. While no single catastrophic public breach has been widely documented as a defining incident, the sheer volume of disclosed CVEs suggests persistent challenges in securing the codebase against common web application attack vectors. This pattern highlights the critical need for rigorous security auditing in open-source data tools to prevent exploitation by malicious actors seeking unauthorized access to sensitive organizational data.

Top products by dataease: dataease SQLBot
CVE ID Title CVSS Severity Published
CVE-2026-93660 SQLBot through 1.10.1 Improper Access Control via Dashboard Update — SQLBot CWE-639 6.5 Medium 2026-09-18
CVE-2026-53557 SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution — SQLBot CWE-89 7.7 High 2026-09-17
CVE-2026-53555 Stored XSS via SVG Upload — SQLBot CWE-79 5.1 Medium 2026-09-17
CVE-2026-53556 SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read — SQLBot CWE-89 6.0 Medium 2026-09-17
CVE-2026-53554 SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing — SQLBot CWE-22 7.3 High 2026-09-17
CVE-2023-40772 DataEase 路径遍历漏洞 — DataEase CWE-23 4.3 Medium 2026-09-14
CVE-2026-82879 DataEase before 2.10.26 Access Control Bypass via Share Tickets — dataease CWE-863 6.3 Medium 2026-08-31
CVE-2026-82878 DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Linkage and Chart Endpoints — dataease CWE-862 6.3 Medium 2026-08-31
CVE-2026-45532 DataEase has a Path Traversal Vulnerability — dataease CWE-22 8.7 High 2026-08-18
CVE-2026-72743 SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html — SQLBot CWE-79 5.4 Medium 2026-08-10
CVE-2026-49867 DataEase: Authenticated Stored XSS in DataEase Template Static Resources — dataease CWE-79 - - 2026-07-15
CVE-2026-46684 DataEase: Unauthorized Command Execution Vulnerability — dataease CWE-347 - - 2026-07-15
CVE-2026-45320 DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection — dataease CWE-89 - - 2026-07-15
CVE-2026-45535 DataEase: Stored SQL Injection Vulnerability — dataease CWE-89 - - 2026-07-15
CVE-2026-45533 DataEase: Path Traversal Vulnerability — dataease CWE-22 - - 2026-07-15
CVE-2026-50124 DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper — dataease CWE-434 - - 2026-07-15
CVE-2026-50030 DataEase: Arbitrary SQL execution in preview path (direct data disclosure) — dataease CWE-89 - - 2026-07-15
CVE-2026-45419 DataEase: Arbitrary File Write Vulnerability — dataease CWE-22 - - 2026-07-15
CVE-2026-45417 DataEase: SQL injection vulnerability — dataease CWE-89 - - 2026-07-15
CVE-2026-45534 DataEase: RCE Vulnerability — dataease CWE-94 - - 2026-07-15
CVE-2026-50530 DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets — dataease CWE-639 - - 2026-07-07
CVE-2026-50529 DataEase: Link Token Leakage Prior to Share Password/Ticket Validation — dataease CWE-863 - - 2026-07-07
CVE-2026-55647 DataEase: authenticated stored XSS in the dashboard text components — dataease CWE-79 - - 2026-07-07
CVE-2026-55635 DataEase: Authenticated SQL Injection in Chart Quota Filters — dataease CWE-89 - - 2026-07-07
CVE-2026-57172 DataEase: Hardcoded JWT Signing Secret in ShareLink — dataease CWE-321 - - 2026-07-07
CVE-2026-53751 DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE) — dataease CWE-94 - - 2026-07-07
CVE-2026-53730 DataEase: Unauthorized Access to Engine Database via previewSql Endpoint — dataease CWE-862 - - 2026-07-07
CVE-2026-55633 DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass — dataease CWE-434 - - 2026-07-07
CVE-2026-55631 DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management — dataease CWE-22 - - 2026-07-07
CVE-2026-53729 DataEase ExportCenter IDOR allows cross-user export task access — dataease CWE-639 - - 2026-07-07

This page lists every published CVE security advisory associated with dataease. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.