Dbgate
Dbgate: vulnerabilities and CVEs
Dbgate has 17 published vulnerabilities, 15 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months15
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101069 | Medium (5.5) | 0.76% | — | Sep 28, 2026 | A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of… |
| CVE-2026-101068 | Medium (5.5) | 0.76% | — | Sep 28, 2026 | A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a… |
| CVE-2026-101066 | Medium (5.5) | 0.69% | — | Sep 28, 2026 | A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the… |
| CVE-2026-101070 | Medium (5.5) | 0.73% | — | Sep 28, 2026 | A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The… |
| CVE-2026-101067 | Medium (5.5) | 0.69% | — | Sep 28, 2026 | A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the… |
| CVE-2026-97226 | Medium (5.3) | 0.34% | — | Sep 24, 2026 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation… |
| CVE-2026-97225 | Medium (5.3) | 0.24% | — | Sep 24, 2026 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument… |
| CVE-2026-85176 | High (8.7) | 0.63% | — | Sep 3, 2026 | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass… |
| CVE-2026-47670 | Critical (9.4) | 1.8% | — | Jul 23, 2026 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by… |
| CVE-2026-47669 | Critical (9.3) | 0.52% | — | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the… |
| CVE-2026-47668 | Critical (10) | 3.9% | — | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script… |
| CVE-2026-48017 | High (8.8) | 0.58% | — | Jun 15, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template… |
| CVE-2026-6216 | Low (2) | 0.33% | — | Apr 13, 2026 | A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the… |
| CVE-2026-6215 | Low (2.1) | 0.34% | — | Apr 13, 2026 | A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side… |
| CVE-2026-34725 | High (8.2) | 0.19% | — | Apr 2, 2026 | DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without… |
| CVE-2025-50185 | High (7) | 0.41% | — | Jul 26, 2025 | DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve… |
| CVE-2025-50184 | High (7.1) | 0.62% | — | Jul 26, 2025 | DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory.… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.