« Volver al listado

Depomo

Depomo Chartbrew: vulnerabilidades y CVE

Depomo Chartbrew tiene 19 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE19
Últimos 12 meses19
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-65980Alta (7.9)0.46%—21 sept 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in…
CVE-2026-61852Media (5.8)0.36%—21 sept 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in…
CVE-2026-61851Media (6.5)0.47%—21 sept 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in…
CVE-2026-61743Media (6.3)0.40%—21 sept 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to…
CVE-2026-41518Alta (7.6)0.34%—4 jun 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In versions 4.9.0 through 5.0.0, an authenticated user with project-editor permissions can…
CVE-2026-40904Alta (8.1)0.40%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes multiple dataset and dataRequest endpoints that…
CVE-2026-40603Media (6.5)0.41%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that returns a project's report…
CVE-2026-40601Alta (7.5)0.52%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes POST /api/chart/:chart_id/query without authentication.…
CVE-2026-40600Alta (8.1)0.40%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to one project to update…
CVE-2026-40595Alta (7.5)0.46%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only…
CVE-2026-35514Media (6.5)0.38%—30 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token,…
CVE-2026-32252Alta (7.7)0.40%—10 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew in GET…
CVE-2026-30232Alta (7.8)0.40%—10 abr 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with…
CVE-2026-27605Media (5.4)0.31%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the application allows uploading files (project logos) without…
CVE-2026-27603Alta (8.7)0.47%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the chart filter endpoint POST…
CVE-2026-27005Alta (8.8)0.71%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries…
CVE-2026-25888Alta (8.8)0.91%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API.…
CVE-2026-25887Alta (7.2)0.92%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB…
CVE-2026-25877Media (6.5)0.35%—6 mar 2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, the application performs authorization checks based solely on the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System3
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application1
  4. T1550.001 Application Access Token1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.