Vendor
DataEase vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 33 vulnerabilities in DataEase: 0 in the last 7 days and 29 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53557, was published on 17 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 29
- Critical, all time
- 0
- Exploited in the wild
- 0
About DataEase
An open-source data visualization and analysis platform.
DataEase technologies
Latest DataEase vulnerabilities
- CVE-2026-53557: DataEase SQLBot second-order SQL injection in datasource deletioninfoCVSS 7.2EPSS 0.3%
- CVE-2026-53556: DataEase SQLBot SQL injection in previewData endpointinfoCVSS 7.1EPSS 0.5%
- CVE-2026-53555: DataEase SQLBot stored cross-site scripting in assistant UI logo uploadinfoCVSS 7.1EPSS 0.5%
- CVE-2026-53554: DataEase SQLBot arbitrary code execution in parseExcelinfoCVSS 8.8EPSS 0.4%
- CVE-2023-40772: DataEase directory traversal in StaticResourceControllermediumCVSS 4.3EPSS 1.1%
- CVE-2026-90529: DataEase cross-site scripting in symbolic map tooltiplowCVSS 3.5EPSS 0.4%
- CVE-2026-82879: DataEase access control bypass in sharing link modulemediumCVSS 6.3EPSS 0.4%
- CVE-2026-82878: DataEase authorization bypass on geographic and dashboard APIsmediumCVSS 6.3EPSS 0.3%
- CVE-2026-45532: DataEase path traversal in static resource endpointinfoCVSS 7.5EPSS 0.5%
- CVE-2026-50124: DataEase RCE via Zip Protocol and H2 Database File UploadinfoCVSS 7.1
- CVE-2026-50030: DataEase SQL injection in SQL preview APIinfoCVSS 7.1
- CVE-2026-49867: DataEase stored XSS in template static resourcesinfoCVSS 6.3
- CVE-2026-46684: DataEase Enterprise authentication bypass and remote code executioninfoCVSS 9.5
- CVE-2026-45535: DataEase stored SQL injection in SQL-type datasetsinfoCVSS 8.7
- CVE-2026-45534: DataEase Remote Code Execution in Redshift datasource connectioninfoCVSS 9
- CVE-2026-45533: DataEase path traversal in export-center bulk delete APIinfoCVSS 8.3
- CVE-2026-45419: DataEase path traversal and arbitrary file write in template managementinfoCVSS 8.5
- CVE-2026-45417: DataEase SQL injection in CalciteProvider datasource checkinfoCVSS 8.7
- CVE-2026-45320: DataEase SQL injection in dashboard SQL variablesinfoCVSS 8.7
- CVE-2026-57172: DataEase hardcoded JWT signature key in ShareSecretManageinfoCVSS 8.3
- CVE-2026-55647: DataEase stored XSS in dashboard text componentsinfoCVSS 5.1
- CVE-2026-55635: DataEase SQL injection in chart quota and Y-axis filtersinfoCVSS 8.7
- CVE-2026-55633: DataEase remote code execution via H2 zip protocol bypass in FontManageinfoCVSS 8.7
- CVE-2026-55631: DataEase path traversal in font management moduleinfoCVSS 7.2
- CVE-2026-53751: DataEase H2 JDBC URL validation bypass in datasource managementinfoCVSS 8.7
Most severe DataEase vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33324: dataease SQLBot prompt injection in Text2SQL chat interfacehighCVSS 8.8EPSS 0.6%
- CVE-2026-82879: DataEase access control bypass in sharing link modulemediumCVSS 6.3EPSS 0.4%
- CVE-2026-82878: DataEase authorization bypass on geographic and dashboard APIsmediumCVSS 6.3EPSS 0.3%
- CVE-2026-5417: Dataease SQLbot SSRF in Elasticsearch HandlermediumCVSS 4.7EPSS 0.2%
- CVE-2026-8724: DataEase SQL injection in SqlparserUtils.transFiltermediumCVSS 4.7
- CVE-2023-40772: DataEase directory traversal in StaticResourceControllermediumCVSS 4.3EPSS 1.1%
- CVE-2026-90529: DataEase cross-site scripting in symbolic map tooltiplowCVSS 3.5EPSS 0.4%
- CVE-2026-46684: DataEase Enterprise authentication bypass and remote code executioninfoCVSS 9.5
- CVE-2026-45534: DataEase Remote Code Execution in Redshift datasource connectioninfoCVSS 9
- CVE-2026-53554: DataEase SQLBot arbitrary code execution in parseExcelinfoCVSS 8.8EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 10 | 0 | |
| 13 Jul 2026 | 10 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 5 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/dataease.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "DataEase vulnerabilities", https://junglewise.ai/threats/vendors/dataease, 26 September 2026.