📦 Metersphere

by Metersphere

🔍 What is Metersphere?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53639

CRITICAL CVSS 9.8 Jul 14, 2025

This SQL injection vulnerability in MeterSphere allows attackers to execute arbitrary SQL commands through the sortField parameter in API endpoints. This could lead to data theft, modification, or del...

CVE-2023-29944

CRITICAL CVSS 9.8 May 8, 2023

Metersphere v1.20.20-lts-79d354a6 contains a remote command execution vulnerability in the custom code snippet function of the system workbench. Attackers can execute arbitrary system commands, potent...

CVE-2023-25573

HIGH CVSS 8.6 Mar 9, 2023

This vulnerability allows any user to download any file from the MeterSphere testing platform without authentication. It affects all MeterSphere users running vulnerable versions, potentially exposing...

CVE-2024-37161

MEDIUM CVSS 4.0 Jun 11, 2024

MeterSphere versions before 1.10.1-lts contain a stored cross-site scripting (XSS) vulnerability in the step editor. This allows attackers to inject malicious scripts that execute in users' browsers w...