Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dataease — Vulnerabilities & Security Advisories 93

Browse all 93 CVE security advisories affecting dataease. AI-powered Chinese analysis, POCs, and references for each vulnerability.

DataEase is an open-source data visualization and analytics tool designed to simplify business intelligence by enabling users to create dashboards from diverse data sources. Despite its utility, the platform has accumulated 71 recorded Common Vulnerabilities and Exposures, indicating significant historical security hygiene issues. Analysis of these vulnerabilities reveals a prevalence of remote code execution, cross-site scripting, and authentication bypass flaws, often stemming from insufficient input validation and improper access control mechanisms. These defects frequently allow unauthenticated attackers to compromise system integrity or escalate privileges within the application environment. While no single catastrophic public breach has been widely documented as a defining incident, the sheer volume of disclosed CVEs suggests persistent challenges in securing the codebase against common web application attack vectors. This pattern highlights the critical need for rigorous security auditing in open-source data tools to prevent exploitation by malicious actors seeking unauthorized access to sensitive organizational data.

Found 10 results / 93Clear Filters
Top products by dataease: dataease SQLBot
Medium2026-08-11
Use v-dompurify-html in SQText to prevent XSS by AAtomical · Pull Request #1309 · dataease/SQLBot · GitHub
High2026-08-11
[BUG] SQText dashboard component uses v-html instead of v-dompurify-html · Issue #1308 · dataease/SQLBot
High2026-07-16
fix: 修复导入模版漏洞 · dataease/dataease@b00d9e3 · GitHub
High2026-07-16
Authenticated Stored XSS in DataEase Template Static Resources · Advisory · dataease/dataease · GitHub
HighCVE-2026-454192026-07-16
Arbitrary File Write Vulnerability · Advisory · dataease/dataease · GitHub
Unknown2026-07-16
fix: 【漏洞】修复目录穿越漏洞 · dataease/dataease@d34f413 · GitHub
High2026-07-16
fix: 【漏洞】修复sql注入 · dataease/dataease@f1c7204 · GitHub
HighCVE-2026-454172026-07-16
SQL injection vulnerability · Advisory · dataease/dataease · GitHub
Critical2026-07-16
DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection · Advisory · dataease/dataease · GitHub
High2026-07-16
fix: 【漏洞】修复SQL 注入 · dataease/dataease@22930a4 · GitHub
HighCVE-2024-455342026-07-16
RCE Vulnerability · Advisory · dataease/dataease · GitHub
HighCVE-2024-455332026-07-16
Path Traversal Vulnerability · Advisory · dataease/dataease · GitHub
HighCVE-2024-45352026-07-16
Stored SQL Injection Vulnerability · Advisory · dataease/dataease · GitHub
High2026-07-16
fix:【漏洞】修复删除下载任务时,路径遍历漏洞 · dataease/dataease@dba0803 · GitHub
HighCVE-2024-50302026-07-16
Arbitrary SQL execution in preview path (direct data disclosure) · Advisory · dataease/dataease · GitHub
HighCVE-2026-501242026-07-16
Remote Code Execution (RCE) via Zip Protocol & File Dropper · Advisory · dataease/dataease · GitHub
Critical2026-07-16
fix: 【漏洞】Remote Code Execution (RCE) via Zip Protocol & File Dropper · dataease/dataease@a7bffa7 · GitHub
HighCVE-2026-466942026-07-16
Unauthorized Command Execution Vulnerability · Advisory · dataease/dataease · GitHub
Critical2026-07-16
fix: 【漏洞】修复unauthorized command execution vulnerability · dataease/dataease@3efda9d · GitHub
High2026-07-08
fix: 任意文件删除 · dataease/dataease@57e90bd · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with dataease. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.