{"schema_version":1,"title":"DbGate vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in DbGate: 2 in the last 7 days and 6 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-97226, was published on 24 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/dbgate","json_url":"https://junglewise.ai/threats/vendors/dbgate.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/dbgate","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":9,"critical":3,"exploited":0,"last_7_days":2,"last_30_days":3,"last_90_days":6,"last_365_days":9},"latest":[{"cve":"CVE-2026-97226","cvss":6.3,"epss":0.0034,"slug":"cve-2026-97226-a-vulnerability-has-been-found-in-dbgate-up-to-7-2-5-7-3-1","title":"DbGate path traversal in file endpoint","severity":"medium","exploited":false,"published_at":"2026-09-24T16:17:29.09+00:00","url":"https://junglewise.ai/threats/cve-2026-97226-a-vulnerability-has-been-found-in-dbgate-up-to-7-2-5-7-3-1"},{"cve":"CVE-2026-97225","cvss":6.3,"epss":0.0024,"slug":"cve-2026-97225-a-flaw-has-been-found-in-dbgate-up-to-7-2-5-beta-5-this-affects","title":"DbGate code injection in JSON Runner comment handling","severity":"medium","exploited":false,"published_at":"2026-09-24T16:17:28.88+00:00","url":"https://junglewise.ai/threats/cve-2026-97225-a-flaw-has-been-found-in-dbgate-up-to-7-2-5-beta-5-this-affects"},{"cve":"CVE-2026-85176","cvss":8.8,"epss":0.0063,"slug":"cve-2026-85176-dbgate-jsldata-controller-arbitrary-file-access","title":"DbGate jsldata controller arbitrary file access","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-85176-dbgate-jsldata-controller-arbitrary-file-access"},{"cve":"CVE-2026-47670","cvss":4,"epss":0.0176,"slug":"cve-2026-47670-dbgate-os-command-injection-in-load-reader-endpoint","title":"DbGate OS command injection in load-reader endpoint","severity":"critical","exploited":false,"published_at":"2026-07-23T20:17:08.5+00:00","url":"https://junglewise.ai/threats/cve-2026-47670-dbgate-os-command-injection-in-load-reader-endpoint"},{"cve":"CVE-2026-47669","cvss":4,"epss":0.0052,"slug":"cve-2026-47669-dbgate-path-traversal-in-unzipdirectory-archive-extraction","title":"DbGate path traversal in unzipDirectory archive extraction","severity":"critical","exploited":false,"published_at":"2026-07-23T20:17:08.357+00:00","url":"https://junglewise.ai/threats/cve-2026-47669-dbgate-path-traversal-in-unzipdirectory-archive-extraction"},{"cve":"CVE-2026-47668","cvss":10,"epss":0.0388,"slug":"cve-2026-47668-dbgate-remote-code-execution-in-json-script-runner","title":"DbGate remote code execution in JSON script runner","severity":"critical","exploited":false,"published_at":"2026-07-23T18:16:53.35+00:00","url":"https://junglewise.ai/threats/cve-2026-47668-dbgate-remote-code-execution-in-json-script-runner"},{"cve":"CVE-2026-48017","cvss":8.8,"epss":0.0058,"slug":"cve-2026-48017-dbgate-code-injection-in-load-reader-endpoint","title":"DbGate code injection in load-reader endpoint","severity":"high","exploited":false,"published_at":"2026-06-15T22:16:16.937+00:00","url":"https://junglewise.ai/threats/cve-2026-48017-dbgate-code-injection-in-load-reader-endpoint"},{"cve":"CVE-2026-6216","cvss":3.5,"epss":0.0033,"slug":"cve-2026-6216-dbgate-cross-site-scripting-in-svg-icon-string-handler","title":"DbGate cross site scripting in SVG Icon String Handler","severity":"low","exploited":false,"published_at":"2026-04-13T21:16:32.003+00:00","url":"https://junglewise.ai/threats/cve-2026-6216-dbgate-cross-site-scripting-in-svg-icon-string-handler"},{"cve":"CVE-2026-34725","cvss":8.2,"epss":0.002,"slug":"cve-2026-34725-dbgate-stored-xss-and-rce-via-unsanitized-svg-icons","title":"DbGate stored XSS and RCE via unsanitized SVG icons","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:33.253+00:00","url":"https://junglewise.ai/threats/cve-2026-34725-dbgate-stored-xss-and-rce-via-unsanitized-svg-icons"}],"vendor":{"hub":true,"name":"DbGate","slug":"dbgate","homepage":"https://dbgate.org/","description":"DbGate is an open-source project providing a cross-platform database administration tool.","url":"https://junglewise.ai/threats/vendors/dbgate"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":3,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-47668","cvss":10,"epss":0.0388,"slug":"cve-2026-47668-dbgate-remote-code-execution-in-json-script-runner","title":"DbGate remote code execution in JSON script runner","severity":"critical","exploited":false,"published_at":"2026-07-23T18:16:53.35+00:00","url":"https://junglewise.ai/threats/cve-2026-47668-dbgate-remote-code-execution-in-json-script-runner"},{"cve":"CVE-2026-47670","cvss":4,"epss":0.0176,"slug":"cve-2026-47670-dbgate-os-command-injection-in-load-reader-endpoint","title":"DbGate OS command injection in load-reader endpoint","severity":"critical","exploited":false,"published_at":"2026-07-23T20:17:08.5+00:00","url":"https://junglewise.ai/threats/cve-2026-47670-dbgate-os-command-injection-in-load-reader-endpoint"},{"cve":"CVE-2026-47669","cvss":4,"epss":0.0052,"slug":"cve-2026-47669-dbgate-path-traversal-in-unzipdirectory-archive-extraction","title":"DbGate path traversal in unzipDirectory archive extraction","severity":"critical","exploited":false,"published_at":"2026-07-23T20:17:08.357+00:00","url":"https://junglewise.ai/threats/cve-2026-47669-dbgate-path-traversal-in-unzipdirectory-archive-extraction"},{"cve":"CVE-2026-85176","cvss":8.8,"epss":0.0063,"slug":"cve-2026-85176-dbgate-jsldata-controller-arbitrary-file-access","title":"DbGate jsldata controller arbitrary file access","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:38.607+00:00","url":"https://junglewise.ai/threats/cve-2026-85176-dbgate-jsldata-controller-arbitrary-file-access"},{"cve":"CVE-2026-48017","cvss":8.8,"epss":0.0058,"slug":"cve-2026-48017-dbgate-code-injection-in-load-reader-endpoint","title":"DbGate code injection in load-reader endpoint","severity":"high","exploited":false,"published_at":"2026-06-15T22:16:16.937+00:00","url":"https://junglewise.ai/threats/cve-2026-48017-dbgate-code-injection-in-load-reader-endpoint"},{"cve":"CVE-2026-34725","cvss":8.2,"epss":0.002,"slug":"cve-2026-34725-dbgate-stored-xss-and-rce-via-unsanitized-svg-icons","title":"DbGate stored XSS and RCE via unsanitized SVG icons","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:33.253+00:00","url":"https://junglewise.ai/threats/cve-2026-34725-dbgate-stored-xss-and-rce-via-unsanitized-svg-icons"},{"cve":"CVE-2026-97226","cvss":6.3,"epss":0.0034,"slug":"cve-2026-97226-a-vulnerability-has-been-found-in-dbgate-up-to-7-2-5-7-3-1","title":"DbGate path traversal in file endpoint","severity":"medium","exploited":false,"published_at":"2026-09-24T16:17:29.09+00:00","url":"https://junglewise.ai/threats/cve-2026-97226-a-vulnerability-has-been-found-in-dbgate-up-to-7-2-5-7-3-1"},{"cve":"CVE-2026-97225","cvss":6.3,"epss":0.0024,"slug":"cve-2026-97225-a-flaw-has-been-found-in-dbgate-up-to-7-2-5-beta-5-this-affects","title":"DbGate code injection in JSON Runner comment handling","severity":"medium","exploited":false,"published_at":"2026-09-24T16:17:28.88+00:00","url":"https://junglewise.ai/threats/cve-2026-97225-a-flaw-has-been-found-in-dbgate-up-to-7-2-5-beta-5-this-affects"},{"cve":"CVE-2026-6216","cvss":3.5,"epss":0.0033,"slug":"cve-2026-6216-dbgate-cross-site-scripting-in-svg-icon-string-handler","title":"DbGate cross site scripting in SVG Icon String Handler","severity":"low","exploited":false,"published_at":"2026-04-13T21:16:32.003+00:00","url":"https://junglewise.ai/threats/cve-2026-6216-dbgate-cross-site-scripting-in-svg-icon-string-handler"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"name":"DbGate","slug":"dbgate","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/dbgate"}]}