VendorsEngknowageall versions
Vulnerabilities

Eng Knowage

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2023-38702
Knowage Server vulnerable to path traversal via upload functionality
Published 2023-08-04 · Modified
9.9EPSS 0.012
CVE-2019-13188
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
Published 2019-09-05 · Modified
9.8EPSS 0.025
CVE-2025-59954
Knowage Contains a Remote Code Execution Vulnerability
Published 2025-09-29 · Analyzed
9.8EPSS 0.005
CVE-2021-30055
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.
Published 2021-04-05 · Modified
8.8EPSS 0.016
CVE-2019-13348
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
Published 2019-08-28 · Modified
8.8EPSS 0.015
CVE-2023-37472
Query injection in Knowage server
Published 2023-07-14 · Modified
7.7EPSS 0.007
CVE-2023-35154
Knowage-Server vulnerable to account validation bypass
Published 2023-06-23 · Modified
7.2EPSS 0.004
CVE-2023-36819
Knowage-Server vulnerable to Path traversal in download functionalities
Published 2023-07-03 · Modified
6.5EPSS 0.008
CVE-2025-58441
Knowage is vulnerable to blind server-side request forgery (SSRF)
Published 2026-01-07 · Analyzed
6.5EPSS 0.002
CVE-2021-30213
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.
Published 2021-05-12 · Modified
6.1EPSS 0.027
CVE-2021-30058
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter.
Published 2021-04-05 · Modified
6.1EPSS 0.010
CVE-2019-13189
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
Published 2019-08-28 · Modified
6.1EPSS 0.009
CVE-2018-12355
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
Published 2018-06-13 · Modified
6.1EPSS 0.008
CVE-2022-39295
Improper Neutralization of Alternate XSS Syntax in Knowage-Server
Published 2022-10-13 · Modified
6.1EPSS 0.006
CVE-2021-30214
Knowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name' parameter.
Published 2021-05-12 · Modified
5.4EPSS 0.238
CVE-2021-30056
Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can lead to data leakage.
Published 2021-04-05 · Modified
5.4EPSS 0.006
CVE-2021-30212
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.
Published 2021-05-12 · Modified
5.4EPSS 0.006
CVE-2021-30211
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.
Published 2021-05-12 · Modified
5.4EPSS 0.005
CVE-2019-13190
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Published 2019-09-05 · Modified
5.3EPSS 0.014
CVE-2025-55007
Knowage vulnerable to server-side request forgery
Published 2025-09-01 · Analyzed
5.3EPSS 0.002
CVE-2021-30057
A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters.
Published 2021-04-05 · Modified
4.8EPSS 0.007