Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

metersphere — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting metersphere. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MeterSphere serves as an open-source continuous testing platform for APIs, UIs, and performance, primarily used in DevSecOps workflows. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and access control flaws. The platform's security posture has been impacted by multiple CVEs, with some instances allowing unauthorized access or system compromise due to insecure default configurations and insufficient authentication mechanisms. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities highlights ongoing challenges in secure development practices within the continuous testing ecosystem.

Top products by metersphere: metersphere
CVE ID Title CVSS Severity Published
CVE-2025-62604 MeterSphere logic flaw allows retrieval of arbitrary user information — metersphere CWE-200 7.5AI High AI 2025-10-22
CVE-2025-53639 Metersphere has SQL Injection Vulnerability in Sorting Field — metersphere CWE-89 8.8AI High AI 2025-07-14
CVE-2024-37161 MeterSphere front-end editor stores XSS vulnerability — metersphere CWE-79 4.0 Medium 2024-06-11
CVE-2024-36118 Unauthorized viewing of workspace test cases in MeterSphere — metersphere CWE-200 3.5 Low 2024-05-30
CVE-2024-32467 Meteraphsere vulnerable to unauthorized viewing by workspace members — metersphere CWE-200 5.7 Medium 2024-04-25
CVE-2023-50267 MeterSphere horizontal privilege escalation vulnerability of resources in project scope. — metersphere CWE-269 4.3 Medium 2023-12-28
CVE-2023-41878 Weak password of selenium VNC in MeterSphere — metersphere CWE-798 4.6 Medium 2023-09-26
CVE-2023-38494 The cloud version of the MeterSphere interface leaks some sensitive data without authentication — metersphere CWE-200 5.9 Medium 2023-08-04
CVE-2023-37461 Path traversal in metersphere — metersphere CWE-22 5.6 Medium 2023-07-17
CVE-2023-35937 Metersphere missing permission check — metersphere CWE-862 6.0 Medium 2023-07-06
CVE-2023-32699 MeterSphere denial of service vulnerability — metersphere CWE-770 6.5 Medium 2023-05-30
CVE-2023-30550 IDOR vulnerability exists in metersphere — metersphere CWE-639 6.8 Medium 2023-05-04
CVE-2023-25814 Arbitrary File Read Vulnerability in metersphere — metersphere CWE-22 7.1 High 2023-03-09
CVE-2023-25573 Improper access control to download file in metersphere — metersphere CWE-862 8.6 High 2023-03-09
CVE-2022-46178 Path Traversal In MeterSpere allows file upload to any path — metersphere CWE-22 7.4 High 2022-12-29
CVE-2022-23544 Server-Side Request Forgery in Metersphere leads to Cross-Site Scripting — metersphere CWE-918 7.2 High 2022-12-27
CVE-2022-23512 Metersphere is vulnerable to Path Injection. — metersphere CWE-22 7.7 High 2022-12-14

This page lists every published CVE security advisory associated with metersphere. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.