📦 Superset

by Apache

🔍 What is Superset?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-53947

CRITICAL CVSS 9.8 Dec 9, 2024

This SQL injection vulnerability in Apache Superset allows attackers to bypass SQL authorization by exploiting unvalidated PostgreSQL functions. Attackers can execute arbitrary SQL commands, potential...

CVE-2023-49657

CRITICAL CVSS 9.6 Jan 23, 2024

This stored cross-site scripting (XSS) vulnerability in Apache Superset allows authenticated attackers with create/update permissions to inject malicious scripts into charts or dashboards. When other ...

CVE-2022-27479

CRITICAL CVSS 9.8 Apr 13, 2022

CVE-2022-27479 is a critical SQL injection vulnerability in Apache Superset that allows attackers to execute arbitrary SQL commands through chart data requests. This affects all Apache Superset instan...

CVE-2025-27696

HIGH CVSS 8.8 May 13, 2025

This vulnerability allows authenticated users with read-only permissions in Apache Superset to take ownership of dashboards, charts, or datasets. This affects all Apache Superset deployments through v...

CVE-2023-49734

HIGH CVSS 7.7 Dec 19, 2023

This vulnerability allows authenticated Gamma users in Apache Superset to gain unauthorized write permissions to charts they create on dashboards. The flaw enables privilege escalation where users can...

CVE-2021-41971

HIGH CVSS 8.8 Oct 18, 2021

This vulnerability allows authenticated attackers to perform SQL injection attacks in Apache Superset when template processing is enabled. It affects Apache Superset versions up to and including 1.3.0...

CVE-2026-23983

MEDIUM CVSS 6.5 Feb 24, 2026

Authenticated users in Apache Superset can exploit a disabled-by-default tagging feature to retrieve sensitive user data including password hashes and email addresses. This affects all Apache Superset...

CVE-2026-23980

MEDIUM CVSS 6.5 Feb 24, 2026

This SQL injection vulnerability in Apache Superset allows authenticated users with read access to execute arbitrary SQL commands through the sqlExpression or where parameters. The vulnerability enabl...

CVE-2025-55673

MEDIUM CVSS 4.3 Aug 14, 2025

This vulnerability allows guest users in Apache Superset to access database schema information through the /chart/data endpoint. The API response improperly includes query details that reveal table na...

CVE-2025-55674

MEDIUM CVSS 6.5 Aug 14, 2025

This vulnerability allows attackers to bypass Apache Superset's DISALLOWED_SQL_FUNCTIONS security feature using a special inline block technique. Users with SQL Lab access can execute SQL functions th...

CVE-2025-55675

MEDIUM CVSS 6.5 Aug 14, 2025

Apache Superset has an improper access control vulnerability where authenticated users can enumerate protected datasources they shouldn't access. By manipulating the datasource_id parameter in the /ex...

CVE-2024-53949

MEDIUM CVSS 6.5 Dec 9, 2024

Apache Superset has an improper authorization vulnerability when FAB_ADD_SECURITY_API is enabled (disabled by default). This allows lower-privilege users to access security API endpoints they shouldn'...

CVE-2024-39887

MEDIUM CVSS 4.3 Jul 16, 2024

This SQL injection vulnerability in Apache Superset allows attackers to bypass SQL authorization by exploiting improperly sanitized PostgreSQL functions. It affects all Apache Superset installations b...

CVE-2024-34693

MEDIUM CVSS 6.8 Jun 20, 2024

This vulnerability allows authenticated attackers in Apache Superset to create MariaDB connections with local_infile enabled, potentially reading arbitrary files from the web server if both MariaDB se...