📦 Metabase

by Metabase

🔍 What is Metabase?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-37470

CRITICAL CVSS 10.0 Aug 4, 2023

CVE-2023-37470 is a critical remote code execution vulnerability in Metabase that allows attackers to execute arbitrary code on the server by injecting malicious commands into H2 database connection s...

CVE-2023-38646

CRITICAL CVSS 9.8 Jul 21, 2023

CVE-2023-38646 is a critical remote code execution vulnerability in Metabase that allows unauthenticated attackers to execute arbitrary commands on the server with the server's privilege level. This a...

CVE-2021-41277

CRITICAL CVSS 10.0 Nov 17, 2021

This vulnerability in Metabase allows attackers to exploit the custom GeoJSON map feature to perform local file inclusion attacks. By submitting malicious URLs that aren't validated, attackers can rea...

CVE-2026-27464

HIGH CVSS 7.7 Feb 21, 2026

This vulnerability allows authenticated users in Metabase to extract sensitive information including database credentials via template evaluation in email notifications. It affects Metabase instances ...

CVE-2022-24854

HIGH CVSS 8.0 Apr 14, 2022

This vulnerability in Metabase allows attackers with SQL permissions on one SQLite database to attach and query across multiple SQLite databases if they know the file paths. Only Metabase users utiliz...

CVE-2025-27141

MEDIUM CVSS 6.5 Feb 24, 2025

In Metabase Enterprise Edition, users with impersonation permissions can access cached query results from other users, potentially viewing data they shouldn't have permission to see. This affects Ente...