VendorsDpgasparflask-appbuilderall versions
Vulnerabilities

Dpgaspar Flask-appbuilder -

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2024-25128
Flask-AppBuilder incorrect authentication when using auth type OpenID
Published 2024-02-28 · Analyzed
9.1EPSS 0.009
CVE-2021-41265
Improper Authentication in Flask-AppBuilder
Published 2021-12-09 · Modified
8.8EPSS 0.013
CVE-2023-29005
No Rate Limiting on Login AUTH DB
Published 2023-04-10 · Modified
7.5EPSS 0.006
CVE-2021-32805
URL Redirection to Untrusted Site ('Open Redirect') in Flask-AppBuilder
Published 2021-09-08 · Modified
7.2EPSS 0.007
CVE-2025-58065
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Published 2025-09-11 · Analyzed
6.5EPSS 0.004
CVE-2022-24776
Open Redirect in Flask-AppBuilder
Published 2022-03-24 · Modified
6.1EPSS 0.010
CVE-2024-27083
Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
Published 2024-02-28 · Analyzed
6.1EPSS 0.006
CVE-2025-32962
Flask-AppBuilder open redirect vulnerability using HTTP host injection
Published 2025-05-16 · Analyzed
6.1EPSS 0.002
CVE-2024-45314
Flask-AppBuilder login form allows browser to cache sensitive fields
Published 2024-09-04 · Analyzed
5.5EPSS 0.003
CVE-2021-29621
Observable Response Discrepancy in Flask-AppBuilder
Published 2021-06-07 · Modified
5.3EPSS 0.034
CVE-2022-21659
Observable Response Discrepancy in Flask-AppBuilder
Published 2022-01-31 · Modified
5.3EPSS 0.010
CVE-2025-24023
Observable Response Discrepancy in flask-appbuilder
Published 2025-03-03 · Analyzed
5.3EPSS 0.003
CVE-2022-31177
Possible to infer sensitive information through query strings in Flask-AppBuilder
Published 2022-08-01 · Modified
2.7EPSS 0.007