Dataease
Dataease: vulnerabilidades y CVE
Dataease tiene 97 vulnerabilidades publicadas, 47 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE97
Últimos 12 meses47
Críticas17
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40772 | Media (4.3) | 1.1% | — | 14 sept 2026 | A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component. |
| CVE-2026-90529 | Media (5.1) | 0.35% | — | 13 sept 2026 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the… |
| CVE-2026-82879 | Media (5.3) | 0.36% | — | 31 ago 2026 | DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another… |
| CVE-2026-82878 | Media (5.3) | 0.34% | — | 31 ago 2026 | DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other… |
| CVE-2026-45532 | Alta (8.7) | 0.52% | — | 18 ago 2026 | DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only… |
| CVE-2026-50124 | Alta (7.1) | 0.56% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses… |
| CVE-2026-50030 | Alta (7.1) | 0.47% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetDataApi.previewSql/previewSqlCheck through /de2api/datasetData/previewSql, accepts… |
| CVE-2026-49867 | Media (6.3) | 0.47% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources let authenticated users submit TemplateManageRequest.staticResource through POST… |
| CVE-2026-46684 | Crítica (9.5) | 0.32% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only… |
| CVE-2026-45535 | Alta (8.7) | 0.38% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and… |
| CVE-2026-45534 | Crítica (9) | 0.64% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from… |
| CVE-2026-45533 | Alta (8.3) | 0.46% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass… |
| CVE-2026-45419 | Alta (8.5) | 0.46% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save… |
| CVE-2026-45417 | Alta (8.7) | 0.38% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the resulting SQL with… |
| CVE-2026-45320 | Alta (8.7) | 0.47% | — | 15 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose final branch returns raw user… |
| CVE-2026-57172 | Alta (8.3) | 0.45% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a… |
| CVE-2026-55647 | Media (5.1) | 0.47% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side HTML sanitization, allowing an… |
| CVE-2026-55635 | Alta (8.7) | 0.41% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated SQL in Quota2SQLObj.getYWheres() without… |
| CVE-2026-55633 | Alta (8.7) | 0.80% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf… |
| CVE-2026-55631 | Alta (7.2) | 0.46% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName when creating a font record; when the record… |
| CVE-2026-53751 | Alta (8.7) | 0.60% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between… |
| CVE-2026-53730 | Alta (8.7) | 0.36% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any authenticated… |
| CVE-2026-53729 | Alta (8.7) | 0.64% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or… |
| CVE-2026-50530 | Alta (7.1) | 0.41% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether… |
| CVE-2026-50529 | Alta (8.7) | 0.50% | — | 7 jul 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share password or ticket,… |
| CVE-2026-8724 | Baja (2) | 0.52% | — | 17 may 2026 | A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection.… |
| CVE-2026-40901 | Alta (7.5) | 0.76% | — | 16 abr 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer… |
| CVE-2026-40900 | Alta (8.7) | 0.52% | — | 16 abr 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in… |
| CVE-2026-40899 | Alta (8.3) | 0.43% | — | 16 abr 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses… |
| CVE-2026-33207 | Alta (8.6) | 0.52% | — | 16 abr 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in… |