VendorsApachesupersetany version
Vulnerabilities

Apache Superset any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2021-32609
XSS vulnerability on Explore page
Published 2021-10-18 · Modified
5.4EPSS 0.017
CVE-2022-43718
Apache Superset: Cross-Site Scripting vulnerability on upload forms
Published 2023-01-16 · Modified
5.4EPSS 0.013
CVE-2022-43720
Apache Superset: Improper rendering of user input
Published 2023-01-16 · Modified
5.4EPSS 0.013
CVE-2022-43717
Apache Superset: Cross-Site Scripting on dashboards
Published 2023-01-16 · Modified
5.4EPSS 0.013
CVE-2022-41703
Apache Superset: SQL injection vulnerability in adhoc clauses
Published 2023-01-16 · Modified
5.4EPSS 0.012
CVE-2023-36387
Apache Superset: Improper API permission for low privilege users
Published 2023-09-06 · Modified
5.4EPSS 0.011
CVE-2023-36388
Apache Superset: Improper API permission for low privilege users allows for SSRF
Published 2023-09-06 · Modified
5.4EPSS 0.011
CVE-2023-43701
Apache Superset: Stored XSS on API endpoint
Published 2023-11-27 · Modified
5.4EPSS 0.010
CVE-2022-43721
Apache Superset: Open Redirect Vulnerability
Published 2023-01-16 · Modified
5.4EPSS 0.010
CVE-2024-26016
Apache Superset: Improper authorization validation on dashboards and charts import
Published 2024-02-28 · Modified
5.4EPSS 0.009
CVE-2023-42502
Apache Superset: Open Redirect Vulnerability
Published 2023-11-28 · Modified
5.4EPSS 0.008
CVE-2025-55672
Apache Superset: Stored XSS on charts metadata
Published 2025-08-14 · Modified
5.4EPSS 0.007
CVE-2019-12413
In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.
Published 2019-12-16 · Modified
5.3EPSS 0.028
CVE-2019-12414
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab
Published 2019-12-16 · Modified
5.3EPSS 0.028
CVE-2022-45438
Apache Superset: Dashboard metadata information leak
Published 2023-01-16 · Modified
5.3EPSS 0.012
CVE-2024-53948
Apache Superset: Error verbosity exposes metadata in analytics databases
Published 2024-12-09 · Analyzed
5.3EPSS 0.009
CVE-2025-55673
Apache Superset: Metadata exposure in embedded charts
Published 2025-08-14 · Modified
5.3EPSS 0.006
CVE-2026-23981
Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification
Published 2026-07-30 · Analyzed
5.3EPSS 0.004
CVE-2023-27523
Apache Superset: Improper data permission validation on Jinja templated queries
Published 2023-09-06 · Modified
5.0EPSS 0.010
CVE-2021-37839
Improper access to dataset metadata information
Published 2022-07-06 · Modified
4.3EPSS 0.014
CVE-2023-27526
Apache Superset: Improper Authorization check on import charts
Published 2023-09-06 · Modified
4.3EPSS 0.012
CVE-2023-39264
Apache Superset: Stack traces enabled by default
Published 2023-09-06 · Modified
4.3EPSS 0.011
CVE-2023-32672
Apache Superset: SQL parser edge case bypasses data access authorization
Published 2023-09-06 · Modified
4.3EPSS 0.010
CVE-2023-42505
Apache Superset: Sensitive information disclosure on db connection details
Published 2023-11-28 · Modified
4.3EPSS 0.010
CVE-2024-27315
Apache Superset: Improper error handling on alerts
Published 2024-02-28 · Analyzed
4.3EPSS 0.010
CVE-2024-24772
Apache Superset: Improper Neutralisation of custom SQL on embedded context
Published 2024-02-28 · Modified
4.3EPSS 0.010
CVE-2023-42501
Apache Superset: Unnecessary read permissions within the Gamma role
Published 2023-11-27 · Modified
4.3EPSS 0.009
CVE-2023-27525
Apache Superset: Incorrect default permissions for Gamma role
Published 2023-04-17 · Modified
4.3EPSS 0.008
CVE-2024-28148
Apache Superset: Incorrect datasource authorization on explore REST API
Published 2024-05-07 · Analyzed
4.3EPSS 0.007
← Prev2 / 2