Metersphere
Metersphere: vulnerabilidades y CVE
Metersphere tiene 21 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses1
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-62604 | Media (5.3) | 0.42% | — | 22 oct 2025 | MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information. This allows an unauthenticated attacker to log in to the system as… |
| CVE-2025-53639 | Media (5.1) | 0.40% | — | 14 jul 2025 | MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply crafted input to… |
| CVE-2024-37161 | Media (6.1) | 0.36% | — | 11 jun 2024 | MeterSphere is an open source continuous testing platform. Prior to version 1.10.1-lts, the system's step editor stores cross-site scripting vulnerabilities. Version 1.10.1-lts fixes this issue. |
| CVE-2024-36118 | Media (4.3) | 0.30% | — | 30 may 2024 | MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond their authority. This issue has been… |
| CVE-2024-32467 | Media (6.5) | 0.53% | — | 25 abr 2024 | MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissions can view member information from other workspaces beyond their authority. Version 2.10.14-lts… |
| CVE-2023-50267 | Media (4.3) | 0.34% | — | 28 dic 2023 | MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in… |
| CVE-2023-41878 | Crítica (9.8) | 0.68% | — | 27 sept 2023 | MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a… |
| CVE-2023-38494 | Alta (7.5) | 0.47% | — | 4 ago 2023 | MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers.… |
| CVE-2023-37461 | Crítica (9.8) | 0.63% | — | 17 jul 2023 | Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../` which may cause metersphere to attempt to overwrite an existing file… |
| CVE-2023-35937 | Alta (8.8) | 0.71% | — | 6 jul 2023 | Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by… |
| CVE-2023-32699 | Media (6.5) | 0.59% | — | 30 may 2023 | MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service. The `checkUserPassword` method is used to check whether the password provided by the user matches… |
| CVE-2023-29944 | Crítica (9.8) | 2.1% | — | 8 may 2023 | Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench |
| CVE-2023-30550 | Media (4.5) | 0.67% | — | 4 may 2023 | MeterSphere is an open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing, and performance testing. This IDOR vulnerability allows the administrator of a project… |
| CVE-2023-25814 | Media (6.5) | 0.86% | — | 9 mar 2023 | metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which… |
| CVE-2023-25573 | Alta (7.5) | 52% | — | 9 mar 2023 | metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without… |
| CVE-2022-46178 | Alta (8.8) | 0.72% | — | 29 dic 2022 | MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not… |
| CVE-2022-23544 | Media (6.1) | 1.6% | — | 28 dic 2022 | MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery… |
| CVE-2022-23512 | Alta (8.1) | 0.83% | — | 14 dic 2022 | MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to… |
| CVE-2021-45790 | Crítica (9.8) | 1.9% | — | 29 sept 2022 | An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands. |
| CVE-2021-45789 | Media (6.5) | 0.89% | — | 29 sept 2022 | An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function. |
| CVE-2021-45788 | Alta (8.8) | 3.0% | — | 29 sept 2022 | Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter. |