Filter
-Infinity
0

MetabaseMetabase vulnerable to circumvention of local link access protection in GeoJson endpoint

2.1
EPSS
0.04%
First published (updated )

MetabaseMetabase Enterprise Edition allows cached questions to leak data to impersonated users

EPSS
0.03%
First published (updated )

MetabaseMetabase sandboxed users could see filter values from other sandboxed users

First published (updated )

MetabaseMetabase vulnerable to remote code execution via POST /api/setup/validate API endpoint

First published (updated )

MetabaseMetabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to exec…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MetabaseMissing SQL permissions check in metabase

First published (updated )

MetabaseMetabase subject to Improper Privilege Management

First published (updated )

MetabaseMetabase subject to Exposure of Sensitive Information to an Unauthorized Actor

First published (updated )

MetabaseSSRF

First published (updated )

MetabaseMetabase vulnerable to circumvention of Locked parameter in Signed Embedding

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MetabaseMetabase's GeoJSON validation doesn't prevent redirects to blocked URLs

First published (updated )

MetabaseMetabase SSO users able to circumvent IdP login by doing password reset

First published (updated )

MetabaseMetabase vulnerable to Remote Code Execution via H2

8.8
First published (updated )

MetabaseMetabase vulnerable to arbitrary SQL execution from queryhash

8.8
First published (updated )

MetabaseFile system exposure in Metabase

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

MetabaseDatabase bypassing any permissions in Metabase via SQlite attach

8.8
First published (updated )

MetabaseXSS vulnerability in Metabase

8.7
First published (updated )

MetabaseMetabase GeoJSON API Local File Inclusion Vulnerability

First published (updated )

MetabaseXSS

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203