CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “dataease”

62 vulnerabilities found for “dataease”

Page 1 of 4

CVE-2023-40183
HIGH7.5

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to obtain user cookies. The program only uses the `ImageIO.read()` method to determine whether the file is an image file or not. There is no whitelisting restriction on file suffixes. This allows the attacker to synthesize the attack code into an image for uploading and change the file extension to html. The attacker may steal user cookies by accessing links. The vulnerability has been fixed in v1.18.11. There are no known workarounds.

dataease / dataease
Network
Published Sep 21, 2023
Page 1 of 4
CVE-2023-40771
HIGH7.5

SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

dataease / dataease
Network
Published Sep 1, 2023
CVE-2023-37258
HIGH8.8

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

dataease / dataease
Network
Published Jul 25, 2023
CVE-2023-37257
MEDIUM5.4

DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.

dataease / dataease
Network
Published Jul 25, 2023
CVE-2023-34463
HIGH8.1

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

dataease / dataease
Network
Published Jun 26, 2023
CVE-2023-35168
MEDIUM6.5

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. Affected versions of DataEase has a privilege bypass vulnerability where ordinary users can gain access to the user database. Exposed information includes md5 hashes of passwords, username, email, and phone number. The vulnerability has been fixed in v1.18.8. Users are advised to upgrade. There are no known workarounds for the vulnerability.

dataease / dataease
Network
Published Jun 26, 2023
CVE-2023-35164
MEDIUM6.3

DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

dataease / dataease
Network
Published Jun 26, 2023
CVE-2023-32310
HIGH8.1

DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulnerable to insecure direct object references (IDOR). This could result in a user deleting another user's dashboard or messages or interfering with the interface for marking messages read. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from upgrading.

dataease / dataease
Network
Published Jun 1, 2023
CVE-2023-33963
CRITICAL9.8

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known workarounds aside from upgrading.

dataease / dataease
Network
Published Jun 1, 2023
CVE-2023-28637
HIGH8.0

DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and the data sources are expected to properly sanitize data. The AWS redshift data source does not provide data sanitization which may lead to remote code execution. This vulnerability has been fixed in v1.18.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

dataease / dataease
Network
Published Mar 28, 2023
CVE-2023-28437
CRITICAL9.8

Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

dataease / dataease
Network
Published Mar 25, 2023
CVE-2023-28435
MEDIUM6.5

Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.

dataease / dataease
Network
Published Mar 24, 2023
CVE-2023-25807
HIGH7.2

DataEase is an open source data visualization and analysis tool. When saving a dashboard on the DataEase platform saved data can be modified and store malicious code. This vulnerability can lead to the execution of malicious code stored by the attacker on the server side when the user accesses the dashboard. The vulnerability has been fixed in version 1.18.3.

dataease / dataease
Network
Published Feb 28, 2023
CVE-2021-38239
HIGH7.5

SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.

dataease / dataease
Network
Published Feb 15, 2023
CVE-2022-39312
CRITICAL9.8

Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In `backend/src/main/java/io/dataease/provider/datasource/JdbcProvider.java`, the `MysqlConfiguration` class does not filter any parameters. If an attacker adds some parameters to a JDBC url and connects to a malicious mysql server, the attacker can trigger the mysql jdbc deserialization vulnerability. Through the deserialization vulnerability, the attacker can execute system commands and obtain server privileges. Version 1.15.2 contains a patch for this issue.

dataease / dataease
Network
Published Oct 25, 2022
CVE-2022-34112
MEDIUM6.5

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normally reserved for the administrator.

dataease / dataease
Network
Published Jul 22, 2022
CVE-2022-34114
HIGH8.8

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

dataease / dataease
Network
Published Jul 22, 2022
CVE-2022-34115
CRITICAL9.8

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

dataease / dataease
Network
Published Jul 22, 2022
CVE-2022-34113
CRITICAL9.8

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

dataease / dataease
Network
Published Jul 22, 2022
CVE-2022-23331
HIGH8.8

In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

dataease / dataease
Network
Published Feb 8, 2022