VendorsApachesupersetany version
Vulnerabilities

Apache Superset any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
Published 2023-04-24 · Analyzed
9.8KEV1 PoCEPSS 0.974
CVE-2018-8021
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
Published 2018-11-07 · Modified
9.81 PoCEPSS 0.528
CVE-2024-39887
Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
Published 2024-07-16 · Modified
9.8EPSS 0.044
CVE-2022-27479
SQL injection vulnerability in chart data API
Published 2022-04-13 · Modified
9.8EPSS 0.029
CVE-2024-53947
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Published 2024-12-09 · Analyzed
9.8EPSS 0.008
CVE-2023-49657
Apache Superset: Stored XSS in Dashboard Title and Chart Title
Published 2024-01-23 · Modified
9.6EPSS 0.008
CVE-2020-13948
While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions < 0.37.1. It was thus possible for an authenticated user to list and access files, environment variables, and process information. Additionally it was possible to set environment variables for the current process, create and update files in folders writable by the web process, and execute arbitrary programs accessible by the web process. All other operations available to the `os` package in Python were also available, even if not explicitly enumerated in this CVE.
Published 2020-09-17 · Modified
8.8EPSS 0.031
CVE-2021-41971
Possible SQL Injection when template processing is enabled
Published 2021-10-18 · Modified
8.8EPSS 0.018
CVE-2023-40610
Apache Superset: Privilege escalation with default examples database
Published 2023-11-27 · Modified
8.8EPSS 0.013
CVE-2025-27696
Apache Superset: Incorrect authorization leading to resource ownership takeover
Published 2025-05-13 · Analyzed
8.8EPSS 0.012
CVE-2023-49736
Apache Superset: SQL Injection on where_in JINJA macro
Published 2023-12-19 · Modified
8.8EPSS 0.012
CVE-2022-43719
Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API
Published 2023-01-16 · Modified
8.8EPSS 0.006
CVE-2020-13952
In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the hashed version of the authenticated users’ password, and access to connection information including the plaintext password for the current connection. It would also be possible to run arbitrary methods on the database connection object for the Presto or Hive connection, allowing the user to bypass security controls internal to Superset. This vulnerability is present in every Apache Superset version < 0.37.2.
Published 2020-09-30 · Modified
8.1EPSS 0.020
CVE-2023-49734
Apache Superset: Privilege Escalation Vulnerability
Published 2023-12-19 · Modified
7.7EPSS 0.010
CVE-2024-53949
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
Published 2024-12-09 · Modified
7.6EPSS 0.007
CVE-2024-55633
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
Published 2024-12-12 · Modified
7.1EPSS 0.028
CVE-2025-48912
Apache Superset: Improper authorization bypass on row level security via SQL Injection
Published 2025-05-30 · Analyzed
7.1EPSS 0.007
CVE-2026-23982
Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass
Published 2026-02-24 · Analyzed
7.1EPSS 0.005
CVE-2026-23984
Apache Superset: SQLLab Read-Only Bypass on PostgreSQL
Published 2026-02-24 · Analyzed
7.1EPSS 0.004
CVE-2024-34693
Apache Superset: Server arbitrary file read
Published 2024-06-20 · Modified
6.8EPSS 0.016
CVE-2023-37941
Apache Superset: Metadata db write access can lead to remote code execution
Published 2023-09-06 · Modified
6.6EPSS 0.355
CVE-2023-39265
Apache Superset: Possible Unauthorized Registration of SQLite Database Connections
Published 2023-09-06 · Modified
6.5EPSS 0.862
CVE-2021-44451
API sensitive information leak
Published 2022-02-01 · Modified
6.5EPSS 0.079
CVE-2023-30776
Apache Superset: Database connection password leak
Published 2023-04-24 · Modified
6.5EPSS 0.021
CVE-2021-42250
Possible log injection
Published 2021-11-17 · Modified
6.5EPSS 0.018
CVE-2024-23952
Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104)
Published 2024-02-14 · Modified
6.5EPSS 0.017
CVE-2023-46104
Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb
Published 2023-12-19 · Modified
6.5EPSS 0.017
CVE-2021-41972
Credentials leak
Published 2021-11-12 · Modified
6.5EPSS 0.015
CVE-2023-42504
Apache Superset: Lack of rate limiting allows for possible denial of service
Published 2023-11-28 · Modified
6.5EPSS 0.011
CVE-2023-25504
Apache Superset: Possible SSRF on import datasets
Published 2023-04-17 · Modified
6.5EPSS 0.010
CVE-2024-24773
Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
Published 2024-02-28 · Modified
6.5EPSS 0.008
CVE-2024-24779
Apache Superset: Improper data authorization when creating a new dataset
Published 2024-02-28 · Modified
6.5EPSS 0.007
CVE-2025-55674
Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions
Published 2025-08-14 · Modified
6.5EPSS 0.007
CVE-2026-23980
Apache Superset: Improper Neutralization of Special Elements used in a SQL Command
Published 2026-02-24 · Analyzed
6.5EPSS 0.006
CVE-2026-23969
Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering
Published 2026-02-24 · Analyzed
6.5EPSS 0.006
CVE-2025-55675
Apache Superset: Incorrect datasource authorization on REST API
Published 2025-08-14 · Modified
6.5EPSS 0.005
CVE-2026-23983
Apache Superset: Sensitive Data Exposure via REST API (disabled by default)
Published 2026-02-24 · Analyzed
6.5EPSS 0.004
CVE-2026-23985
Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
Published 2026-07-30 · Analyzed
6.5EPSS 0.004
CVE-2021-28125
Apache Superset Open Redirect
Published 2021-04-27 · Modified
6.1EPSS 0.640
CVE-2021-27907
Apache Superset stored XSS on Dashboard markdown
Published 2021-03-05 · Modified
5.4EPSS 0.864
1 / 2Next →