openrefine
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 5, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenRefine has a path traversal in LoadLanguageCommand
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
Reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
OpenRefine JDBC Attack Vulnerability
Remote Code exec in project import with mysql jdbc url attack
OpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
Monitor openrefine in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.