{"schema_version":1,"title":"flask-appbuilder (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in flask-appbuilder (PyPI): 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-58065, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/flask-appbuilder","json_url":"https://junglewise.ai/threats/technologies/flask-appbuilder.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/flask-appbuilder","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":7,"last_365_days":7},"latest":[{"cve":"CVE-2025-58065","cvss":3.1,"epss":0.004,"slug":"cve-2025-58065-flask-app-builder-has-an-authentication-bypass-vulnerability-when","title":"PYSEC-2026-1378 - Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:04.816469+00:00","url":"https://junglewise.ai/threats/cve-2025-58065-flask-app-builder-has-an-authentication-bypass-vulnerability-when"},{"cve":"CVE-2025-32962","cvss":3.1,"epss":0.0022,"slug":"cve-2025-32962-flask-appbuilder-open-redirect-vulnerability-using-http-host","title":"PYSEC-2026-1379 - Flask-AppBuilder open redirect vulnerability using HTTP host injection","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:52.688627+00:00","url":"https://junglewise.ai/threats/cve-2025-32962-flask-appbuilder-open-redirect-vulnerability-using-http-host"},{"cve":"CVE-2024-45314","cvss":3.1,"epss":0.0027,"slug":"cve-2024-45314-flask-appbuilder-s-login-form-allows-browser-to-cache-sensitive","title":"PYSEC-2026-1382 - Flask-AppBuilder's login form allows browser to cache sensitive fields","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:40.306044+00:00","url":"https://junglewise.ai/threats/cve-2024-45314-flask-appbuilder-s-login-form-allows-browser-to-cache-sensitive"},{"cve":"CVE-2024-27083","cvss":3.1,"epss":0.0057,"slug":"cve-2024-27083-flask-appbuilder-s-oauth-login-page-subject-to-cross-site","title":"PYSEC-2026-1381 - Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.452545+00:00","url":"https://junglewise.ai/threats/cve-2024-27083-flask-appbuilder-s-oauth-login-page-subject-to-cross-site"},{"cve":"CVE-2023-29005","cvss":3.1,"epss":0.0063,"slug":"cve-2023-29005-flask-appbuilder-has-no-rate-limiting-on-login-auth-db","title":"PYSEC-2026-1380 - Flask-AppBuilder Has No Rate Limiting on Login AUTH DB","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:18.206548+00:00","url":"https://junglewise.ai/threats/cve-2023-29005-flask-appbuilder-has-no-rate-limiting-on-login-auth-db"},{"cve":"CVE-2022-24776","cvss":3.1,"epss":0.0097,"slug":"cve-2022-24776-flask-appbuilder-open-redirect-in-database-authentication-login","title":"PYSEC-2026-635 - Open Redirect in Flask-AppBuilder","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.201505+00:00","url":"https://junglewise.ai/threats/cve-2022-24776-flask-appbuilder-open-redirect-in-database-authentication-login"},{"cve":"CVE-2024-25128","cvss":3.1,"epss":0.0086,"slug":"cve-2024-25128-flask-appbuilder-vulnerable-to-incorrect-authentication-when","title":"PYSEC-2026-340 - Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:40.498361+00:00","url":"https://junglewise.ai/threats/cve-2024-25128-flask-appbuilder-vulnerable-to-incorrect-authentication-when"},{"cve":"CVE-2025-24023","cvss":3.1,"epss":0.0033,"slug":"cve-2025-24023-flask-appbuilder-observable-response-discrepancy","title":"PYSEC-2025-15 - Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existin","severity":"low","exploited":false,"published_at":"2025-03-03T16:15:41+00:00","url":"https://junglewise.ai/threats/cve-2025-24023-flask-appbuilder-observable-response-discrepancy"},{"cve":"CVE-2023-34110","cvss":3.1,"epss":0.0068,"slug":"cve-2023-34110-flask-appbuilder-vulnerable-to-possible-disclosure-of-sensitive","title":"PYSEC-2023-94 - Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor wi","severity":"low","exploited":false,"published_at":"2023-06-22T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-34110-flask-appbuilder-vulnerable-to-possible-disclosure-of-sensitive"},{"cve":"CVE-2022-31177","cvss":3.1,"epss":0.0074,"slug":"cve-2022-31177-flask-appbuilder-password-hash-inference-via-query-filtering","title":"PYSEC-2022-247 - Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated","severity":"low","exploited":false,"published_at":"2022-08-01T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31177-flask-appbuilder-password-hash-inference-via-query-filtering"},{"cve":"CVE-2022-21659","cvss":3.1,"epss":0.0095,"slug":"cve-2022-21659-observable-response-discrepancy-in-flask-appbuilder","title":"PYSEC-2022-24 - Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user","severity":"low","exploited":false,"published_at":"2022-01-31T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-21659-observable-response-discrepancy-in-flask-appbuilder"},{"cve":"CVE-2021-41265","cvss":3.1,"epss":0.0129,"slug":"cve-2021-41265-improper-authentication-in-flask-appbuilder","title":"PYSEC-2021-851 - Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability i","severity":"low","exploited":false,"published_at":"2021-12-09T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41265-improper-authentication-in-flask-appbuilder"},{"cve":"CVE-2021-32805","cvss":3.1,"epss":0.007,"slug":"cve-2021-32805-flask-appbuilder-open-redirect-vulnerability","title":"PYSEC-2021-359 - Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an at","severity":"low","exploited":false,"published_at":"2021-09-08T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32805-flask-appbuilder-open-redirect-vulnerability"},{"cve":"CVE-2021-29621","cvss":3.1,"epss":0.034,"slug":"cve-2021-29621-observable-response-discrepancy-in-flask-appbuilder","title":"PYSEC-2021-90 - Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3","severity":"low","exploited":false,"published_at":"2021-06-07T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29621-observable-response-discrepancy-in-flask-appbuilder"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"flask-appbuilder (PyPI)","slug":"flask-appbuilder","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/flask-appbuilder"},"most_severe":[{"cve":"CVE-2021-29621","cvss":3.1,"epss":0.034,"slug":"cve-2021-29621-observable-response-discrepancy-in-flask-appbuilder","title":"PYSEC-2021-90 - Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3","severity":"low","exploited":false,"published_at":"2021-06-07T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29621-observable-response-discrepancy-in-flask-appbuilder"},{"cve":"CVE-2021-41265","cvss":3.1,"epss":0.0129,"slug":"cve-2021-41265-improper-authentication-in-flask-appbuilder","title":"PYSEC-2021-851 - Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability i","severity":"low","exploited":false,"published_at":"2021-12-09T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-41265-improper-authentication-in-flask-appbuilder"},{"cve":"CVE-2022-24776","cvss":3.1,"epss":0.0097,"slug":"cve-2022-24776-flask-appbuilder-open-redirect-in-database-authentication-login","title":"PYSEC-2026-635 - Open Redirect in Flask-AppBuilder","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.201505+00:00","url":"https://junglewise.ai/threats/cve-2022-24776-flask-appbuilder-open-redirect-in-database-authentication-login"},{"cve":"CVE-2022-21659","cvss":3.1,"epss":0.0095,"slug":"cve-2022-21659-observable-response-discrepancy-in-flask-appbuilder","title":"PYSEC-2022-24 - Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user","severity":"low","exploited":false,"published_at":"2022-01-31T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-21659-observable-response-discrepancy-in-flask-appbuilder"},{"cve":"CVE-2024-25128","cvss":3.1,"epss":0.0086,"slug":"cve-2024-25128-flask-appbuilder-vulnerable-to-incorrect-authentication-when","title":"PYSEC-2026-340 - Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:40.498361+00:00","url":"https://junglewise.ai/threats/cve-2024-25128-flask-appbuilder-vulnerable-to-incorrect-authentication-when"},{"cve":"CVE-2022-31177","cvss":3.1,"epss":0.0074,"slug":"cve-2022-31177-flask-appbuilder-password-hash-inference-via-query-filtering","title":"PYSEC-2022-247 - Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated","severity":"low","exploited":false,"published_at":"2022-08-01T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-31177-flask-appbuilder-password-hash-inference-via-query-filtering"},{"cve":"CVE-2021-32805","cvss":3.1,"epss":0.007,"slug":"cve-2021-32805-flask-appbuilder-open-redirect-vulnerability","title":"PYSEC-2021-359 - Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an at","severity":"low","exploited":false,"published_at":"2021-09-08T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32805-flask-appbuilder-open-redirect-vulnerability"},{"cve":"CVE-2023-34110","cvss":3.1,"epss":0.0068,"slug":"cve-2023-34110-flask-appbuilder-vulnerable-to-possible-disclosure-of-sensitive","title":"PYSEC-2023-94 - Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor wi","severity":"low","exploited":false,"published_at":"2023-06-22T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-34110-flask-appbuilder-vulnerable-to-possible-disclosure-of-sensitive"},{"cve":"CVE-2023-29005","cvss":3.1,"epss":0.0063,"slug":"cve-2023-29005-flask-appbuilder-has-no-rate-limiting-on-login-auth-db","title":"PYSEC-2026-1380 - Flask-AppBuilder Has No Rate Limiting on Login AUTH DB","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:18.206548+00:00","url":"https://junglewise.ai/threats/cve-2023-29005-flask-appbuilder-has-no-rate-limiting-on-login-auth-db"},{"cve":"CVE-2024-27083","cvss":3.1,"epss":0.0057,"slug":"cve-2024-27083-flask-appbuilder-s-oauth-login-page-subject-to-cross-site","title":"PYSEC-2026-1381 - Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:33.452545+00:00","url":"https://junglewise.ai/threats/cve-2024-27083-flask-appbuilder-s-oauth-login-page-subject-to-cross-site"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}