CVE-2026-23985Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Medium CVE-2026-23981Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Medium CVE-2026-23969Apache Superset: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity Medium CVE-2026-23980Apache Superset: Improper Neutralization of Special Elements used in a SQL Command Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity Medium CVE-2026-23982Apache Superset: Improper Authorization in Dataset Creation Allows Access Control Bypass Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity High CVE-2026-23983Apache Superset: Sensitive Data Exposure via REST API (disabled by default) Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity Low CVE-2026-23984Apache Superset: SQLLab Read-Only Bypass on PostgreSQL Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity High CVE-2025-55675Apache Superset: Incorrect datasource authorization on REST API Exploitation status Not known exploited Fix YesPublished 08/14/2025 Severity Medium CVE-2025-55674Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions Exploitation status Not known exploited Fix YesPublished 08/14/2025 Severity Medium CVE-2025-55672Apache Superset: Stored XSS on charts metadata Exploitation status Not known exploited Fix YesPublished 08/14/2025 Severity Medium CVE-2025-55673Apache Superset: Metadata exposure in embedded charts Exploitation status Not known exploited Fix YesPublished 08/14/2025 Severity Medium CVE-2025-48912Apache Superset: Improper authorization bypass on row level security via SQL Injection Exploitation status Not known exploited Fix YesPublished 05/30/2025 Severity High CVE-2025-27696Apache Superset: Incorrect authorization leading to resource ownership takeover Exploitation status Not known exploited Fix YesPublished 05/13/2025 Severity Medium CVE-2024-55633Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access Exploitation status Not known exploited Fix YesPublished 12/12/2024 Severity High CVE-2024-53949Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled Exploitation status Not known exploited Fix YesPublished 12/09/2024 Severity High CVE-2024-53948Apache Superset: Error verbosity exposes metadata in analytics databases Exploitation status Not known exploited Fix YesPublished 12/09/2024 Severity Medium CVE-2024-53947Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions Exploitation status Not known exploited Fix YesPublished 12/09/2024 Severity Low CVE-2024-39887Apache Superset: Improper SQL authorisation, parse not checking for specific engine functions Exploitation status Not known exploited Fix YesPublished 07/16/2024 Severity Medium CVE-2024-34693Apache Superset: Server arbitrary file read Exploitation status Not known exploited Fix YesPublished 06/20/2024 Severity Medium CVE-2024-28148Apache Superset: Incorrect datasource authorization on explore REST API Exploitation status Not known exploited Fix YesPublished 05/07/2024 Severity Medium CVE-2024-26016Apache Superset: Improper authorization validation on dashboards and charts import Exploitation status Not known exploited Fix YesPublished 02/28/2024 Severity Medium CVE-2024-24779Apache Superset: Improper data authorization when creating a new dataset Exploitation status Not known exploited Fix YesPublished 02/28/2024 Severity Medium CVE-2024-24772Apache Superset: Improper Neutralisation of custom SQL on embedded context Exploitation status Not known exploited Fix YesPublished 02/28/2024 Severity Medium CVE-2024-24773Apache Superset: Improper validation of SQL statements allows for unauthorized access to data Exploitation status Not known exploited Fix YesPublished 02/28/2024 Severity Medium CVE-2024-27315Apache Superset: Improper error handling on alerts Exploitation status Not known exploited Fix YesPublished 02/28/2024 Severity Medium CVE-2024-23952Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb (version range fix for CVE-2023-46104) Exploitation status Not known exploited Fix YesPublished 02/14/2024 Severity Medium CVE-2023-49657Apache Superset: Stored XSS in Dashboard Title and Chart Title Exploitation status Not known exploited Fix YesPublished 01/23/2024 Severity Critical CVE-2023-49734Apache Superset: Privilege Escalation Vulnerability Exploitation status Not confirmed Fix YesPublished 12/19/2023 Severity High CVE-2023-49736Apache Superset: SQL Injection on where_in JINJA macro Exploitation status Not confirmed Fix YesPublished 12/19/2023 Severity Medium CVE-2023-46104Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb Exploitation status Not known exploited Fix YesPublished 12/19/2023 Severity Medium CVE-2023-42504Apache Superset: Lack of rate limiting allows for possible denial of service Exploitation status Not known exploited Fix YesPublished 11/28/2023 Severity Medium CVE-2023-42505Apache Superset: Sensitive information disclosure on db connection details Exploitation status Not confirmed Fix YesPublished 11/28/2023 Severity Medium CVE-2023-42502Apache Superset: Open Redirect Vulnerability Exploitation status Not confirmed Fix YesPublished 11/28/2023 Severity Medium CVE-2023-43701Apache Superset: Stored XSS on API endpoint Exploitation status Not confirmed Fix YesPublished 11/27/2023 Severity Medium CVE-2023-42501Apache Superset: Unnecessary read permissions within the Gamma role Exploitation status Not known exploited Fix YesPublished 11/27/2023 Severity Medium CVE-2023-40610Apache Superset: Privilege escalation with default examples database Exploitation status Public exploit Fix YesPublished 11/27/2023 Severity Medium CVE-2023-32672Apache Superset: SQL parser edge case bypasses data access authorization Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-37941Apache Superset: Metadata db write access can lead to remote code execution Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-39265Apache Superset: Possible Unauthorized Registration of SQLite Database Connections Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Low CVE-2023-39264Apache Superset: Stack traces enabled by default Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-27523Apache Superset: Improper data permission validation on Jinja templated queries Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-36388Apache Superset: Improper API permission for low privilege users allows for SSRF Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-27526Apache Superset: Improper Authorization check on import charts Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-36387Apache Superset: Improper API permission for low privilege users Exploitation status Not known exploited Fix YesPublished 09/06/2023 Severity Medium CVE-2023-30776Apache Superset: Database connection password leak Exploitation status Not known exploited Fix YesPublished 04/24/2023 Severity Medium CVE-2023-27524Apache Superset: Session validation vulnerability when using provided default SECRET_KEY Exploitation status KEV Fix YesPublished 04/24/2023 Severity High CVE-2023-25504Apache Superset: Possible SSRF on import datasets Exploitation status Not known exploited Fix YesPublished 04/17/2023 Severity Medium CVE-2023-27525Apache Superset: Incorrect default permissions for Gamma role Exploitation status Not known exploited Fix YesPublished 04/17/2023 Severity Low CVE-2022-41703Apache Superset: SQL injection vulnerability in adhoc clauses Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2022-45438Apache Superset: Dashboard metadata information leak Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2022-43721Apache Superset: Open Redirect Vulnerability Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2022-43720Apache Superset: Improper rendering of user input Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2022-43719Apache Superset: Cross Site Request Forgery (CSRF) on accept, request access API Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity High CVE-2022-43718Apache Superset: Cross-Site Scripting vulnerability on upload forms Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2022-43717Apache Superset: Cross-Site Scripting on dashboards Exploitation status Not known exploited Fix YesPublished 01/16/2023 Severity Medium CVE-2021-37839Improper access to dataset metadata information Exploitation status Not confirmed Fix YesPublished 07/06/2022 Severity Unknown CVE-2022-27479SQL injection vulnerability in chart data API Exploitation status Not confirmed Fix YesPublished 04/13/2022 Severity Unknown CVE-2021-44451API sensitive information leak Exploitation status Not confirmed Fix Not confirmed Published 02/01/2022 Severity Unknown CVE-2021-42250Possible log injection Exploitation status Not confirmed Fix Not confirmed Published 11/17/2021 Severity Unknown CVE-2021-41972Credentials leak Exploitation status Not confirmed Fix Not confirmed Published 11/12/2021 Severity Unknown CVE-2021-41971Possible SQL Injection when template processing is enabled Exploitation status Not confirmed Fix YesPublished 10/18/2021 Severity Unknown CVE-2021-32609XSS vulnerability on Explore page Exploitation status Not confirmed Fix Not confirmed Published 10/18/2021 Severity Unknown CVE-2021-28125Apache Superset Open Redirect Exploitation status Not confirmed Fix Not confirmed Published 04/27/2021 Severity Unknown CVE-2021-27907Apache Superset stored XSS on Dashboard markdown Exploitation status Not confirmed Fix Not confirmed Published 03/05/2021 Severity Unknown CVE-2020-1932Exploitation status Not confirmed Fix Not confirmed Published 01/28/2020 Severity Unknown