See how metabase compares to other vendors in security performance
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/resetpassword' database endpoint and gain administrator access to the connected Metabase instance.
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.