Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.43% | — | Fit2cloud SqlbotAI | 18/9/2026 | 22/9/2026 | SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view… | |
| Aplazada | Alta (7.7) | 0.34% | — | PostgresqlAIFit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When… | |
| Aplazada | Media (6) | 0.48% | — | PostgresqlAIFit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated… | |
| Aplazada | Media (5.1) | 0.48% | — | Fit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without sanitizing or validating embedded active content. SQLBot later serves… | |
| Aplazada | Alta (7.3) | 0.41% | — | Fit2cloud SqlbotAI | 17/9/2026 | 23/9/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content is stored, writes the content before… | |
| Aplazada | Media (5.1) | 0.30% | — | TinymceAIFit2cloud SqlbotAI | 10/8/2026 | 23/9/2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users… | |
| Analizada | Alta (8.6) | 0.36% | — | Fit2cloud Sqlbot | 13/5/2026 | 17/6/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints. An attacker can… | |
| Analizada | Crítica (9.4) | 0.84% | — | Fit2cloud Sqlbot | 5/5/2026 | 24/7/2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from… | |
| Aplazada | Baja (2) | 0.38% | — | Dataease SqlbotAI | 2/4/2026 | 24/7/2026 | A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes server-side request forgery. The attack may be initiated remotely. The… | |
| Analizada | Alta (8.6) | 1.0% | — | Fit2cloud Sqlbot | 20/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privileged) to fully… | |
| Analizada | Alta (8.7) | 0.48% | — | Fit2cloud Sqlbot | 20/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can exploit the /api/v1/datasource/check… | |
| Analizada | Alta (8.6) | 0.77% | — | Fit2cloud Sqlbot | 19/3/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, unsanitized storage… | |
| Analizada | Baja (2.9) | 0.19% | — | Fit2cloud Sqlbot | 3/3/2026 | 17/6/2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.56% | — | Fit2cloud Sqlbot | 2/3/2026 | 17/6/2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (7.7) | 0.46% | — | Fit2cloud Sqlbot | 21/1/2026 | 17/6/2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a remote unauthenticated attacker to upload arbitrary Excel/CSV files and inject data directly into the… |