« Back to list

Dbgate

Dbgate: vulnerabilities and CVEs

Dbgate has 17 published vulnerabilities, 15 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs17
Last 12 months15
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-101069Medium (5.5)0.76%—Sep 28, 2026
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of…
CVE-2026-101068Medium (5.5)0.76%—Sep 28, 2026
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a…
CVE-2026-101066Medium (5.5)0.69%—Sep 28, 2026
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the…
CVE-2026-101070Medium (5.5)0.73%—Sep 28, 2026
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The…
CVE-2026-101067Medium (5.5)0.69%—Sep 28, 2026
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the…
CVE-2026-97226Medium (5.3)0.34%—Sep 24, 2026
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation…
CVE-2026-97225Medium (5.3)0.24%—Sep 24, 2026
A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument…
CVE-2026-85176High (8.7)0.63%—Sep 3, 2026
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass…
CVE-2026-47670Critical (9.4)1.8%—Jul 23, 2026
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by…
CVE-2026-47669Critical (9.3)0.52%—Jul 23, 2026
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the…
CVE-2026-47668Critical (10)3.9%—Jul 23, 2026
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script…
CVE-2026-48017High (8.8)0.58%—Jun 15, 2026
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template…
CVE-2026-6216Low (2)0.33%—Apr 13, 2026
A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the…
CVE-2026-6215Low (2.1)0.34%—Apr 13, 2026
A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file packages/rest/src/openApiDriver.ts of the component REST/GraphQL. This manipulation causes server-side…
CVE-2026-34725High (8.2)0.19%—Apr 2, 2026
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without…
CVE-2025-50185High (7)0.41%—Jul 26, 2025
DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve…
CVE-2025-50184High (7.1)0.62%—Jul 26, 2025
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory.…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System7
  2. T1190 Exploit Public-Facing Application5
  3. T1210 Exploitation of Remote Services3
  4. T1059 Command and Scripting Interpreter1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.