Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

dataease — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting dataease. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DataEase is an open-source data visualization and analytics tool designed to simplify business intelligence by enabling users to create dashboards from diverse data sources. Despite its utility, the platform has accumulated 71 recorded Common Vulnerabilities and Exposures, indicating significant historical security hygiene issues. Analysis of these vulnerabilities reveals a prevalence of remote code execution, cross-site scripting, and authentication bypass flaws, often stemming from insufficient input validation and improper access control mechanisms. These defects frequently allow unauthenticated attackers to compromise system integrity or escalate privileges within the application environment. While no single catastrophic public breach has been widely documented as a defining incident, the sheer volume of disclosed CVEs suggests persistent challenges in securing the codebase against common web application attack vectors. This pattern highlights the critical need for rigorous security auditing in open-source data tools to prevent exploitation by malicious actors seeking unauthorized access to sensitive organizational data.

Top products by dataease: dataease SQLBot
CVE ID Title CVSS Severity Published
CVE-2023-37258 DataEase has a SQL injection vulnerability that can bypass blacklists — dataease CWE-89 8.8 High 2023-07-25
CVE-2023-37257 The DataEase panel and dataset have a stored XSS vulnerability — dataease CWE-79 5.4 Medium 2023-07-25
CVE-2023-35164 Unauthorized users can manipulate a dashboard created by an administrator in DataEase — dataease CWE-862 6.3 Medium 2023-06-26
CVE-2023-34463 Unauthorized users can delete applications in DataEase — dataease CWE-862 8.1 High 2023-06-26
CVE-2023-35168 DataEase has a privilege bypass vulnerability — dataease CWE-732 6.5 Medium 2023-06-26
CVE-2023-33963 DataEase data source has deserialization vulnerability — dataease CWE-502 9.8 Critical 2023-06-01
CVE-2023-32310 DataEase API interface has IDOR vulnerability — dataease CWE-639 8.1 High 2023-06-01
CVE-2023-28637 DataEase AWS redshift data source exists for remote code execution vulnerability — dataease CWE-74 8.0 High 2023-03-28
CVE-2023-28437 SQL injection vulnerability due to the keyword blacklist for defending against SQL injection will be bypassed — dataease CWE-89 9.8 Critical 2023-03-24
CVE-2023-28435 Dataease file upload interface does not verify permission or file type — dataease CWE-79 6.5 Medium 2023-03-24
CVE-2023-25807 DataEase dashboard has a stored XSS vulnerability — dataease CWE-79 7.2 High 2023-02-28
CVE-2022-39312 Dataease Mysql Data Source JDBC Connection Parameters Not Verified Leads to Deserialization Vulnerability — dataease CWE-20 9.8 Critical 2022-10-25

This page lists every published CVE security advisory associated with dataease. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.